Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wqpm-3q37-8x6w

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An improper input validation vulnerability of ZOOK software (remote administration tool) could allow a remote attacker to create arbitrary file. The ZOOK viewer has the "Tight file CMD" function to create file. An attacker could create and execute arbitrary file in the ZOOK agent program using "Tight file CMD" without authority.

An improper input validation vulnerability of ZOOK software (remote administration tool) could allow a remote attacker to create arbitrary file. The ZOOK viewer has the "Tight file CMD" function to create file. An attacker could create and execute arbitrary file in the ZOOK agent program using "Tight file CMD" without authority.

EPSS

Процентиль: 79%
0.01269
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9
nvd
больше 4 лет назад

An improper input validation vulnerability of ZOOK software (remote administration tool) could allow a remote attacker to create arbitrary file. The ZOOK viewer has the "Tight file CMD" function to create file. An attacker could create and execute arbitrary file in the ZOOK agent program using "Tight file CMD" without authority.

EPSS

Процентиль: 79%
0.01269
Низкий

Дефекты

CWE-20