Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-1853

Опубликовано: 17 фев. 2020
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

GaussDB 200 with version of 6.5.1 have a path traversal vulnerability. Due to insufficient input path validation, an authenticated attacker can traverse directories and download files to a specific directory. Successful exploit may cause information leakage.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:huawei:gaussdb_200:6.5.1:*:*:*:*:*:*:*

EPSS

Процентиль: 45%
0.00227
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

github
больше 3 лет назад

GaussDB 200 with version of 6.5.1 have a path traversal vulnerability. Due to insufficient input path validation, an authenticated attacker can traverse directories and download files to a specific directory. Successful exploit may cause information leakage.

EPSS

Процентиль: 45%
0.00227
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-22