Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wjqp-6v92-rwg3

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The myCIOScn ActiveX control (myCIOScn.dll) in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to write to arbitrary files by specifying an arbitrary filename in the MyCioScan.Scan.ReportFile parameter, as demonstrated by injecting script into a log file and executing arbitrary code using the MyCioScan.Scan.Start method.

The myCIOScn ActiveX control (myCIOScn.dll) in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to write to arbitrary files by specifying an arbitrary filename in the MyCioScan.Scan.ReportFile parameter, as demonstrated by injecting script into a log file and executing arbitrary code using the MyCioScan.Scan.Start method.

EPSS

Процентиль: 68%
0.00579
Низкий

Дефекты

CWE-94

Связанные уязвимости

nvd
больше 14 лет назад

The myCIOScn ActiveX control (myCIOScn.dll) in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to write to arbitrary files by specifying an arbitrary filename in the MyCioScan.Scan.ReportFile parameter, as demonstrated by injecting script into a log file and executing arbitrary code using the MyCioScan.Scan.Start method.

EPSS

Процентиль: 68%
0.00579
Низкий

Дефекты

CWE-94