Описание
A buffer overflow in the web server of Flexense DupScout Enterprise 10.0.18 allows a remote anonymous attacker to execute code as SYSTEM by overflowing the sid parameter via a GET /settings&sid= attack.
Ссылки
- ExploitThird Party Advisory
- Product
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- Product
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:flexense:dupscout:10.0.18:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 87%
0.03403
Низкий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-120
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
A buffer overflow in the web server of Flexense DupScout Enterprise 10.0.18 allows a remote anonymous attacker to execute code as SYSTEM by overflowing the sid parameter via a GET /settings&sid= attack.
EPSS
Процентиль: 87%
0.03403
Низкий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-120