Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-7875

Опубликовано: 28 окт. 2021
Источник: nvd
CVSS3: 7.5
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged for code execution.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:dext5:dext5upload:*:*:*:*:*:*:*:*
Версия до 5.0.0.117 (включая)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

EPSS

Процентиль: 61%
0.00409
Низкий

7.5 High

CVSS3

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-494
CWE-494

Связанные уязвимости

github
больше 3 лет назад

DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged for code execution.

EPSS

Процентиль: 61%
0.00409
Низкий

7.5 High

CVSS3

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-494
CWE-494