Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v2xx-6ch2-qjrp

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

The Log Viewer function in the Check Point FireWall-1 GUI for Solaris 3.0b through 4.1 SP2 does not check for the existence of '.log' files when saving files, which allows (1) remote authenticated users to overwrite arbitrary files ending in '.log', or (2) local users to overwrite arbitrary files via a symlink attack.

The Log Viewer function in the Check Point FireWall-1 GUI for Solaris 3.0b through 4.1 SP2 does not check for the existence of '.log' files when saving files, which allows (1) remote authenticated users to overwrite arbitrary files ending in '.log', or (2) local users to overwrite arbitrary files via a symlink attack.

EPSS

Процентиль: 70%
0.00638
Низкий

Связанные уязвимости

nvd
почти 24 года назад

The Log Viewer function in the Check Point FireWall-1 GUI for Solaris 3.0b through 4.1 SP2 does not check for the existence of '.log' files when saving files, which allows (1) remote authenticated users to overwrite arbitrary files ending in '.log', or (2) local users to overwrite arbitrary files via a symlink attack.

EPSS

Процентиль: 70%
0.00638
Низкий