Описание
Eval injection vulnerability in tDiary 2.0.3 and 2.1.4.200 61127 allows remote authenticated users to execute arbitrary Ruby code via unspecified vectors, possibly related to incorrect input validation by (1) conf.rhtml and (2) i.conf.rhtml. NOTE: some of these details are obtained from third party information.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:tdiary:tdiary:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:tdiary:tdiary:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:tdiary:tdiary:2.0.3:*:*:*:*:*:*:*
EPSS
Процентиль: 74%
0.00863
Низкий
6 Medium
CVSS2
Дефекты
CWE-20
Связанные уязвимости
debian
почти 19 лет назад
Eval injection vulnerability in tDiary 2.0.3 and 2.1.4.200 61127 allow ...
github
больше 3 лет назад
Eval injection vulnerability in tDiary 2.0.3 and 2.1.4.200 61127 allows remote authenticated users to execute arbitrary Ruby code via unspecified vectors, possibly related to incorrect input validation by (1) conf.rhtml and (2) i.conf.rhtml. NOTE: some of these details are obtained from third party information.
EPSS
Процентиль: 74%
0.00863
Низкий
6 Medium
CVSS2
Дефекты
CWE-20