Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rhvw-j7hf-3g3r

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An XSS vulnerability resides in the hostname field of the diag_ping.php page in pfsense before 2.4.5 version. After passing inputs to the command and executing this command, the $result variable is not sanitized before it is printed.

An XSS vulnerability resides in the hostname field of the diag_ping.php page in pfsense before 2.4.5 version. After passing inputs to the command and executing this command, the $result variable is not sanitized before it is printed.

EPSS

Процентиль: 85%
0.02605
Низкий

Связанные уязвимости

CVSS3: 6.1
nvd
почти 6 лет назад

An XSS vulnerability resides in the hostname field of the diag_ping.php page in pfsense before 2.4.5 version. After passing inputs to the command and executing this command, the $result variable is not sanitized before it is printed.

EPSS

Процентиль: 85%
0.02605
Низкий