Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-1000002

Опубликовано: 17 июл. 2017
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Средний

Описание

ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution. ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal vulnerability in the Course Icon component resulting in information disclosure.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:atutor:atutor:*:*:*:*:*:*:*:*
Версия до 2.2.1 (включая)

EPSS

Процентиль: 98%
0.60219
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution. ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal vulnerability in the Course Icon component resulting in information disclosure.

EPSS

Процентиль: 98%
0.60219
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-22