Описание
An issue was discovered in FAUST iServer before 9.0.019.019.7. For each URL request, it accesses the corresponding .fau file on the operating system without preventing %2e%2e%5c directory traversal.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ProductVendor Advisory
- ExploitThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ProductVendor Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 9.0.017.017.1-3 (включая) до 9.0.019.019.7 (исключая)
cpe:2.3:a:land-software:faust_iserver:*:*:*:*:*:*:*:*
EPSS
Процентиль: 100%
0.90222
Критический
7.5 High
CVSS3
7.8 High
CVSS2
Дефекты
CWE-22
Связанные уязвимости
github
около 4 лет назад
An issue was discovered in FAUST iServer before 9.0.019.019.7. For each URL request, it accesses the corresponding .fau file on the operating system without preventing %2e%2e%5c directory traversal.
EPSS
Процентиль: 100%
0.90222
Критический
7.5 High
CVSS3
7.8 High
CVSS2
Дефекты
CWE-22