Описание
The (1) dlback.php and (2) dlback.cgi scripts in Hot Links allow remote attackers to obtain sensitive information and download the database via a direct request with a modified dl parameter.
Ссылки
- Third Party Advisory
- Third Party Advisory
- Permissions Required
- ExploitThird Party AdvisoryVDB Entry
- Not Applicable
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Third Party Advisory
- Permissions Required
- ExploitThird Party AdvisoryVDB Entry
- Not Applicable
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:mrcgiguy:hot_links:-:*:*:*:*:*:*:*
EPSS
Процентиль: 90%
0.05445
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-200
Связанные уязвимости
github
почти 4 года назад
The (1) dlback.php and (2) dlback.cgi scripts in Hot Links allow remote attackers to obtain sensitive information and download the database via a direct request with a modified dl parameter.
EPSS
Процентиль: 90%
0.05445
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-200