Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-36667

Опубликовано: 14 сент. 2022
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

Garage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file upload function. The vulnerability exist during adding parts and from the upload function, the attacker can upload PHP Reverse Shell straight away to gain RCE.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:garage_management_system_project:garage_management_system:1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 88%
0.0372
Низкий

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

Garage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file upload function. The vulnerability exist during adding parts and from the upload function, the attacker can upload PHP Reverse Shell straight away to gain RCE.

EPSS

Процентиль: 88%
0.0372
Низкий

8.8 High

CVSS3

Дефекты

CWE-434