Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xx8c-v55p-48rc

Опубликовано: 25 июн. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response and modify the associated code. This modified code can be forwarded and used by a script loaded later in the sequence, allowing for arbitrary file upload into a location where PHP scripts may be executed.

Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response and modify the associated code. This modified code can be forwarded and used by a script loaded later in the sequence, allowing for arbitrary file upload into a location where PHP scripts may be executed.

EPSS

Процентиль: 42%
0.00199
Низкий

7.5 High

CVSS3

Дефекты

CWE-434
CWE-841

Связанные уязвимости

CVSS3: 9.4
nvd
около 3 лет назад

Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the initial file upload page response and modify the associated code. This modified code can be forwarded and used by a script loaded later in the sequence, allowing for arbitrary file upload into a location where PHP scripts may be executed.

CVSS3: 9.4
fstec
около 3 лет назад

Уязвимость обработчика загрузки файлов микропрограммного обеспечения SEPCOS Single Package реле управления и защиты Secheron SEPCOS, позволяющая нарушителю загружать произвольные файлы

EPSS

Процентиль: 42%
0.00199
Низкий

7.5 High

CVSS3

Дефекты

CWE-434
CWE-841