Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rv6x-ghr7-v4f6

Опубликовано: 10 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.6
CVSS3: 7.2

Описание

EIP Plus developed by Hundred Plus has an Arbitrary File Uplaod vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

EIP Plus developed by Hundred Plus has an Arbitrary File Uplaod vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

EPSS

Процентиль: 50%
0.00272
Низкий

8.6 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
nvd
3 месяца назад

EIP Plus developed by Hundred Plus has an Arbitrary File Uplaod vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

EPSS

Процентиль: 50%
0.00272
Низкий

8.6 High

CVSS4

7.2 High

CVSS3

Дефекты

CWE-434