Описание
Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshells, which could lead to arbitrary code execution on the server.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 6 (включая) до 6.5.1 (исключая)Версия от 7 (включая) до 7.2.3 (исключая)
Одно из
cpe:2.3:a:vice:webopac:*:*:*:*:*:*:*:*
cpe:2.3:a:vice:webopac:*:*:*:*:*:*:*:*
EPSS
Процентиль: 83%
0.01946
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-434
Связанные уязвимости
CVSS3: 9.8
github
около 1 года назад
Webopac from Grand Vice info does not properly validate uploaded file types, allowing unauthenticated remote attackers to upload and execute webshells, which could lead to arbitrary code execution on the server.
EPSS
Процентиль: 83%
0.01946
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-434