Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-15270

Опубликовано: 15 нояб. 2017
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Средний

Описание

The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) file. This can be used by attackers to hide data in the Graphical User Interface (GUI) view and create arbitrary entries to a certain extent. Special characters such as '"' and ',' and '\r' are not escaped and can be used to add new entries to the log.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:psftp:psftpd:10.0.4:*:*:*:*:*:*:*

EPSS

Процентиль: 94%
0.13968
Средний

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.3
github
больше 3 лет назад

The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) file. This can be used by attackers to hide data in the Graphical User Interface (GUI) view and create arbitrary entries to a certain extent. Special characters such as '"' and ',' and '\r' are not escaped and can be used to add new entries to the log.

EPSS

Процентиль: 94%
0.13968
Средний

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-20