Описание
Directory traversal vulnerability in commsrss.php in fuzzylime (cms) before 3.01b allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in a files array element for a blogs action, as demonstrated by the files[0] parameter.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:fuzzylime:fuzzylime_\(cms\):3.0:*:*:*:*:*:*:*
cpe:2.3:a:fuzzylime:fuzzylime_\(cms\):3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:fuzzylime:fuzzylime_\(cms\):3.0.1a:*:*:*:*:*:*:*
EPSS
Процентиль: 84%
0.02213
Низкий
10 Critical
CVSS2
Дефекты
CWE-22
Связанные уязвимости
github
больше 3 лет назад
Directory traversal vulnerability in commsrss.php in fuzzylime (cms) before 3.01b allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in a files array element for a blogs action, as demonstrated by the files[0] parameter.
EPSS
Процентиль: 84%
0.02213
Низкий
10 Critical
CVSS2
Дефекты
CWE-22