Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-4595

Опубликовано: 23 нояб. 2023
Источник: nvd
CVSS3: 7.5
CVSS3: 6.5
EPSS Низкий

Описание

An information exposure vulnerability has been found, the exploitation of which could allow a remote user to retrieve sensitive information stored on the server such as credential files, configuration files, application files, etc., simply by appending any of the following parameters to the end of the URL: %00 %0a, %20, %2a, %a0, %aa, %c0 and %ca.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:seattlelab:slmail:5.5.0.4433:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

EPSS

Процентиль: 25%
0.00084
Низкий

7.5 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-538

Связанные уязвимости

CVSS3: 7.5
github
около 2 лет назад

An information exposure vulnerability has been found, the exploitation of which could allow a remote user to retrieve sensitive information stored on the server such as credential files, configuration files, application files, etc., simply by appending any of the following parameters to the end of the URL: %00 %0a, %20, %2a, %a0, %aa, %c0 and %ca.

EPSS

Процентиль: 25%
0.00084
Низкий

7.5 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-538