Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wqpr-5jgg-vf8q

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmware before 10.2.9 allows remote attackers to read arbitrary files and execute arbitrary PHP code via a ..././ (dot dot dot slash dot slash) in the lang Cookie parameter, as demonstrated by a request to login/doLogin.

Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmware before 10.2.9 allows remote attackers to read arbitrary files and execute arbitrary PHP code via a ..././ (dot dot dot slash dot slash) in the lang Cookie parameter, as demonstrated by a request to login/doLogin.

EPSS

Процентиль: 89%
0.05059
Низкий

Дефекты

CWE-22

Связанные уязвимости

nvd
почти 12 лет назад

Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmware before 10.2.9 allows remote attackers to read arbitrary files and execute arbitrary PHP code via a ..././ (dot dot dot slash dot slash) in the lang Cookie parameter, as demonstrated by a request to login/doLogin.

EPSS

Процентиль: 89%
0.05059
Низкий

Дефекты

CWE-22