Описание
eEye SecureIIS versions 1.0.3 and earlier allows a remote attacker to bypass filtering of requests made to SecureIIS by escaping HTML characters within the request, which could allow a remote attacker to use restricted variables and perform directory traversal attacks on vulnerable programs that would otherwise be protected.
Ссылки
- ExploitVendor Advisory
- Vendor Advisory
- ExploitVendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.3 (включая)
Одно из
cpe:2.3:a:eeye_digital_security:secureiis:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:eeye_digital_security:securells:*:*:*:*:*:*:*:*
EPSS
Процентиль: 62%
0.00424
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
eEye SecureIIS versions 1.0.3 and earlier allows a remote attacker to bypass filtering of requests made to SecureIIS by escaping HTML characters within the request, which could allow a remote attacker to use restricted variables and perform directory traversal attacks on vulnerable programs that would otherwise be protected.
EPSS
Процентиль: 62%
0.00424
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other