Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-4367

Опубликовано: 21 дек. 2009
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers to bypass authentication and (1) upload files, (2) download files, (3) list directories, and (4) clear the server cache via crafted SOAP requests with arbitrary Username and Password values, possibly related to a direct request.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sitecore:staging_module:*:080625:*:*:*:*:*:*
Версия до 5.4.0 (включая)

EPSS

Процентиль: 91%
0.06723
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

github
почти 4 года назад

The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers to bypass authentication and (1) upload files, (2) download files, (3) list directories, and (4) clear the server cache via crafted SOAP requests with arbitrary Username and Password values, possibly related to a direct request.

EPSS

Процентиль: 91%
0.06723
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-287