Описание
The management tool in MyLittleBackup up to and including 1.7 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all customers' installations) in web.config, and can be used to send serialized ASP code.
Ссылки
- Broken Link
- Third Party Advisory
- Broken Link
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.7 (включая)
cpe:2.3:a:mylittletools:mylittlebackup:*:*:*:*:*:*:*:*
EPSS
Процентиль: 88%
0.03675
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-502
Связанные уязвимости
github
больше 3 лет назад
The management tool in MyLittleBackup up to and including 1.7 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all customers' installations) in web.config, and can be used to send serialized ASP code.
EPSS
Процентиль: 88%
0.03675
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-502