Описание
LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.
Ссылки
- Release Notes
- Third Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.1.2 (исключая)
cpe:2.3:a:liquidfiles:liquidfiles:*:*:*:*:*:*:*:*
EPSS
Процентиль: 25%
0.00085
Низкий
9.9 Critical
CVSS3
8.8 High
CVSS3
Дефекты
CWE-732
Связанные уязвимости
CVSS3: 9.9
github
6 месяцев назад
LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.
EPSS
Процентиль: 25%
0.00085
Низкий
9.9 Critical
CVSS3
8.8 High
CVSS3
Дефекты
CWE-732