Описание
Absolute path traversal vulnerability in the copy action in index.php in Andrew Godwin ByteHoard 2.1 and earlier allows remote authenticated users to create or overwrite files in other users' directories by specifying the absolute path of the directory in the infolder parameter and simultaneously specifying the filename in the filepath parameter.
Ссылки
- PatchVendor Advisory
- Patch
- Patch
- PatchVendor Advisory
- Patch
- Patch
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:andrew_godwin:bytehoard:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:andrew_godwin:bytehoard:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:andrew_godwin:bytehoard:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:andrew_godwin:bytehoard:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:andrew_godwin:bytehoard:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:andrew_godwin:bytehoard:2.0.5:*:*:*:*:*:*:*
cpe:2.3:a:andrew_godwin:bytehoard:2.0_beta1:*:*:*:*:*:*:*
cpe:2.3:a:andrew_godwin:bytehoard:2.0_beta2:*:*:*:*:*:*:*
cpe:2.3:a:andrew_godwin:bytehoard:2.1_alpha:*:*:*:*:*:*:*
cpe:2.3:a:andrew_godwin:bytehoard:2.1_beta:*:*:*:*:*:*:*
cpe:2.3:a:andrew_godwin:bytehoard:2.1_delta:*:*:*:*:*:*:*
cpe:2.3:a:andrew_godwin:bytehoard:2.1_gamma:*:*:*:*:*:*:*
EPSS
Процентиль: 63%
0.00445
Низкий
4 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Absolute path traversal vulnerability in the copy action in index.php in Andrew Godwin ByteHoard 2.1 and earlier allows remote authenticated users to create or overwrite files in other users' directories by specifying the absolute path of the directory in the infolder parameter and simultaneously specifying the filename in the filepath parameter.
EPSS
Процентиль: 63%
0.00445
Низкий
4 Medium
CVSS2
Дефекты
NVD-CWE-Other