Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-3986

Опубликовано: 25 июл. 2007
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

file.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) 4.6.3 allows remote attackers to bypass authentication via a name parameter that specifies the eventcache directory and a non-GIF file, which causes the $dontvalidate variable to be set to true. NOTE: a separate traversal vulnerability could be leveraged to download arbitrary files.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:securecomputing:securityreporter:4.6.3:*:*:*:*:*:*:*

EPSS

Процентиль: 74%
0.008
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

file.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) 4.6.3 allows remote attackers to bypass authentication via a name parameter that specifies the eventcache directory and a non-GIF file, which causes the $dontvalidate variable to be set to true. NOTE: a separate traversal vulnerability could be leveraged to download arbitrary files.

EPSS

Процентиль: 74%
0.008
Низкий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other