Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vx88-5hj8-432c

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

Analysis of the Bomgar Remote Support Portal JavaStart.jar Applet 52790 and earlier revealed that it is vulnerable to a path traversal vulnerability. The archive can be downloaded from a given Bomgar Remote Support Portal deployment at https://domain/api/content/JavaStart.jar and is callable from an arbitrary website using and/or tags. Successful exploitation results in file creation/modification/deletion in the operating system and with privileges of the user that ran the Java applet.

Analysis of the Bomgar Remote Support Portal JavaStart.jar Applet 52790 and earlier revealed that it is vulnerable to a path traversal vulnerability. The archive can be downloaded from a given Bomgar Remote Support Portal deployment at https://domain/api/content/JavaStart.jar and is callable from an arbitrary website using and/or tags. Successful exploitation results in file creation/modification/deletion in the operating system and with privileges of the user that ran the Java applet.

EPSS

Процентиль: 65%
0.00493
Низкий

10 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 10
nvd
почти 8 лет назад

Analysis of the Bomgar Remote Support Portal JavaStart.jar Applet 52790 and earlier revealed that it is vulnerable to a path traversal vulnerability. The archive can be downloaded from a given Bomgar Remote Support Portal deployment at https://domain/api/content/JavaStart.jar and is callable from an arbitrary website using <object> and/or <appletHTML> tags. Successful exploitation results in file creation/modification/deletion in the operating system and with privileges of the user that ran the Java applet.

CVSS3: 10
fstec
больше 8 лет назад

Уязвимость компонента JavaStart.jar веб-портала информационно-технической поддержки Bomgar Remote Support Portal, позволяющая нарушителю создавать, изменять или удалять произвольные файлы

EPSS

Процентиль: 65%
0.00493
Низкий

10 Critical

CVSS3

Дефекты

CWE-22