Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xcxj-rfmv-wfv3

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Multiple absolute path traversal vulnerabilities in eLineStudio Site Composer (ESC) 2.6 allow remote attackers to create or delete arbitrary directories via a full pathname in the inpCurrFolder parameter to (1) folderdel_.asp or (2) foldernew.asp in cms/assetmanager/.

Multiple absolute path traversal vulnerabilities in eLineStudio Site Composer (ESC) 2.6 allow remote attackers to create or delete arbitrary directories via a full pathname in the inpCurrFolder parameter to (1) folderdel_.asp or (2) foldernew.asp in cms/assetmanager/.

EPSS

Процентиль: 93%
0.11313
Средний

Дефекты

CWE-22

Связанные уязвимости

nvd
больше 17 лет назад

Multiple absolute path traversal vulnerabilities in eLineStudio Site Composer (ESC) 2.6 allow remote attackers to create or delete arbitrary directories via a full pathname in the inpCurrFolder parameter to (1) folderdel_.asp or (2) foldernew.asp in cms/assetmanager/.

EPSS

Процентиль: 93%
0.11313
Средний

Дефекты

CWE-22