Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w7w6-m6q3-r777

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9

Описание

Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. www/delivery/asyncspc.php was vulnerable to the fairly new Reflected File Download (RFD) web attack vector that enables attackers to gain complete control over a victim's machine by virtually downloading a file from a trusted domain.

Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. www/delivery/asyncspc.php was vulnerable to the fairly new Reflected File Download (RFD) web attack vector that enables attackers to gain complete control over a victim's machine by virtually downloading a file from a trusted domain.

EPSS

Процентиль: 67%
0.0054
Низкий

9 Critical

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 9
nvd
почти 9 лет назад

Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. `www/delivery/asyncspc.php` was vulnerable to the fairly new Reflected File Download (RFD) web attack vector that enables attackers to gain complete control over a victim's machine by virtually downloading a file from a trusted domain.

EPSS

Процентиль: 67%
0.0054
Низкий

9 Critical

CVSS3

Дефекты

CWE-79