Описание
Grand Vice info Co. webopac7 file upload function fails to filter special characters. While logging in with general user’s permission, remote attackers can upload malicious script and execute arbitrary code to control the system or interrupt services.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:vice:webopac:1.8.20160701:*:*:*:*:*:*:*
cpe:2.3:a:vice:webopac:7.1.20160701:*:*:*:*:*:*:*
EPSS
Процентиль: 82%
0.01628
Низкий
8.8 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-434
Связанные уязвимости
github
больше 3 лет назад
Grand Vice info Co. webopac7 file upload function fails to filter special characters. While logging in with general user’s permission, remote attackers can upload malicious script and execute arbitrary code to control the system or interrupt services.
EPSS
Процентиль: 82%
0.01628
Низкий
8.8 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-434