Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xxvh-jcpq-95qv

Опубликовано: 02 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Image parameter in the profile.php component.

File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Image parameter in the profile.php component.

EPSS

Процентиль: 94%
0.15492
Средний

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Image parameter in the profile.php component.

EPSS

Процентиль: 94%
0.15492
Средний

9.8 Critical

CVSS3

Дефекты

CWE-434