Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-10974

Опубликовано: 07 июл. 2017
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Средний

Описание

Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:yaws:yaws:1.91:*:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.54643
Средний

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 9 лет назад

Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product.

CVSS3: 7.5
debian
около 9 лет назад

Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Direc ...

CVSS3: 7.5
github
больше 4 лет назад

Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: this CVE is only about use of an initial /%5C sequence to defeat traversal protection mechanisms; the initial /%5C sequence was apparently not discussed in earlier research on this product.

EPSS

Процентиль: 99%
0.54643
Средний

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22