Описание
Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege to arbitrarily upload files via /common/upload API, which could lead to remote arbitrary code execution.
Ссылки
- ExploitThird Party Advisory
- Third Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:roothub:roothub:2.6.0:*:*:*:*:*:*:*
EPSS
Процентиль: 83%
0.02037
Низкий
8 High
CVSS3
6 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 8
github
почти 4 года назад
Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege to arbitrarily upload files via /common/upload API, which could lead to remote arbitrary code execution.
EPSS
Процентиль: 83%
0.02037
Низкий
8 High
CVSS3
6 Medium
CVSS2
Дефекты
CWE-22