Описание
Directory traversal vulnerability in posts.php in SimpleBBS 1.0.6 through 1.1 allows remote attackers to include and execute arbitrary files via ".." sequences in the language cookie, as demonstrated by by injecting the code into the gl_session cookie of users.php, which is stored in error.log.
Ссылки
- Exploit
- ExploitVendor Advisory
- Exploit
- Exploit
- Exploit
- ExploitVendor Advisory
- Exploit
- Exploit
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:simplemedia:simplebbs:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:simplemedia:simplebbs:1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:simplemedia:simplebbs:1.1:*:*:*:*:*:*:*
EPSS
Процентиль: 84%
0.02623
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
больше 4 лет назад
Directory traversal vulnerability in posts.php in SimpleBBS 1.0.6 through 1.1 allows remote attackers to include and execute arbitrary files via ".." sequences in the language cookie, as demonstrated by by injecting the code into the gl_session cookie of users.php, which is stored in error.log.
EPSS
Процентиль: 84%
0.02623
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other