Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-35380

Опубликовано: 15 фев. 2022
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Высокий

Описание

A Directory Traversal vulnerability exists in Solari di Udine TermTalk Server (TTServer) 3.24.0.2, which lets an unauthenticated malicious user gain access to the files on the remote system by gaining access to the relative path of the file they want to download (http://url:port/file?valore).

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:solari:termtalk_server:3.24.0.2:*:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.73487
Высокий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
github
почти 4 года назад

A Directory Traversal vulnerability exists in Solari di Udine TermTalk Server (TTServer) 3.24.0.2, which lets an unauthenticated malicious user gain access to the files on the remote system by gaining access to the relative path of the file they want to download (http://url:port/file?valore).

EPSS

Процентиль: 99%
0.73487
Высокий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22