Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-9538

Опубликовано: 03 окт. 2017
Источник: nvd
CVSS3: 4.9
CVSS2: 4
EPSS Низкий

Описание

The 'Upload logo from external path' function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to cause a denial of service (permanent display of a "Cannot exit above the top directory" error message throughout the entire web application) via a ".." in the path field. In other words, the denial of service is caused by an incorrect implementation of a directory-traversal protection mechanism.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:solarwinds:network_performance_monitor:*:*:*:*:*:*:*:*
Версия до 12.0.15300.90 (включая)

EPSS

Процентиль: 90%
0.05631
Низкий

4.9 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 4.9
github
больше 3 лет назад

The 'Upload logo from external path' function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to cause a denial of service (permanent display of a "Cannot exit above the top directory" error message throughout the entire web application) via a ".." in the path field. In other words, the denial of service is caused by an incorrect implementation of a directory-traversal protection mechanism.

EPSS

Процентиль: 90%
0.05631
Низкий

4.9 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-20