Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x2r2-p764-47gc

Опубликовано: 05 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.9

Описание

LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.

LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.

EPSS

Процентиль: 25%
0.00085
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 9.9
nvd
6 месяцев назад

LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.

EPSS

Процентиль: 25%
0.00085
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-732