Описание
Sunnet eHRD has inadequate filtering for special characters in URLs, which allows a remote attacker to perform path traversal attacks without authentication, access restricted paths and download system files.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:sun:ehrd:8:*:*:*:*:*:*:*
cpe:2.3:a:sun:ehrd:9:*:*:*:*:*:*:*
EPSS
Процентиль: 64%
0.00471
Низкий
7.5 High
CVSS3
7.8 High
CVSS2
Дефекты
CWE-22
Связанные уязвимости
github
около 4 лет назад
Sunnet eHRD has inadequate filtering for special characters in URLs, which allows a remote attacker to perform path traversal attacks without authentication, access restricted paths and download system files.
EPSS
Процентиль: 64%
0.00471
Низкий
7.5 High
CVSS3
7.8 High
CVSS2
Дефекты
CWE-22