Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-10974

Опубликовано: 07 июл. 2017
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Высокий

Описание

Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:yaws:yaws:1.91:*:*:*:*:*:*:*

EPSS

Процентиль: 100%
0.89548
Высокий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product.

CVSS3: 7.5
debian
больше 8 лет назад

Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Direc ...

CVSS3: 7.5
github
больше 3 лет назад

Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product.

EPSS

Процентиль: 100%
0.89548
Высокий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22