Описание
Multiple directory traversal vulnerabilities in phpAdsNew and phpPgAds before 2.0.6 allow remote attackers to include arbitrary files via a .. (dot dot) in the (1) layerstyle parameter to adlayer.php or (2) language parameter to js-form.php.
Ссылки
- Vendor Advisory
- Patch
- ExploitVendor Advisory
- Vendor Advisory
- Patch
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.0.5 (включая)Версия до 2.0.5 (включая)
Одно из
cpe:2.3:a:phpadsnew:phpadsnew:*:*:*:*:*:*:*:*
cpe:2.3:a:phppgads:phppgads:*:*:*:*:*:*:*:*
EPSS
Процентиль: 77%
0.01818
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
больше 4 лет назад
Multiple directory traversal vulnerabilities in phpAdsNew and phpPgAds before 2.0.6 allow remote attackers to include arbitrary files via a .. (dot dot) in the (1) layerstyle parameter to adlayer.php or (2) language parameter to js-form.php.
EPSS
Процентиль: 77%
0.01818
Низкий
5 Medium
CVSS2
Дефекты
NVD-CWE-Other