Описание
An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This is exploitable by authenticated users who have local filesystem access.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- Vendor Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.1.13 (исключая)
cpe:2.3:a:ispconfig:ispconfig:*:*:*:*:*:*:*:*
EPSS
Процентиль: 62%
0.00427
Низкий
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-185
Связанные уязвимости
CVSS3: 7.8
github
больше 3 лет назад
An unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code execution. This is exploitable by authenticated users who have local filesystem access.
EPSS
Процентиль: 62%
0.00427
Низкий
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-185