Описание
Webopac from Grand Vice info does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells, which could lead to arbitrary code execution on the server.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 6 (включая) до 6.5.1 (исключая)Версия от 7 (включая) до 7.2.3 (исключая)
Одно из
cpe:2.3:a:vice:webopac:*:*:*:*:*:*:*:*
cpe:2.3:a:vice:webopac:*:*:*:*:*:*:*:*
EPSS
Процентиль: 81%
0.01524
Низкий
8.8 High
CVSS3
Дефекты
CWE-434
Связанные уязвимости
CVSS3: 8.8
github
около 1 года назад
Webopac from Grand Vice info does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells, which could lead to arbitrary code execution on the server.
EPSS
Процентиль: 81%
0.01524
Низкий
8.8 High
CVSS3
Дефекты
CWE-434