Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vg7h-w623-47v4

Опубликовано: 03 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading a file, an attacker can induce the victim server to disclose the username and password hash of the user executing the ACEweb Online software.

ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading a file, an attacker can induce the victim server to disclose the username and password hash of the user executing the ACEweb Online software.

EPSS

Процентиль: 59%
0.00387
Низкий

7.5 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading a file, an attacker can induce the victim server to disclose the username and password hash of the user executing the ACEweb Online software.

EPSS

Процентиль: 59%
0.00387
Низкий

7.5 High

CVSS3

Дефекты

CWE-434