Логотип exploitDog
bind:CVE-2005-2885
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2005-2885

Количество 2

Количество 2

nvd логотип

CVE-2005-2885

больше 20 лет назад

The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which could allow remote attackers to bypass file extension checks and execute arbitrary commands by uploading a file with a different extension, as demonstrated using .inc files.

CVSS2: 7.5
EPSS: Низкий
github логотип

GHSA-q9jr-59gg-37j9

почти 4 года назад

The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which could allow remote attackers to bypass file extension checks and execute arbitrary commands by uploading a file with a different extension, as demonstrated using .inc files.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-2885

The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which could allow remote attackers to bypass file extension checks and execute arbitrary commands by uploading a file with a different extension, as demonstrated using .inc files.

CVSS2: 7.5
10%
Низкий
больше 20 лет назад
github логотип
GHSA-q9jr-59gg-37j9

The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dangerous file extensions, which could allow remote attackers to bypass file extension checks and execute arbitrary commands by uploading a file with a different extension, as demonstrated using .inc files.

10%
Низкий
почти 4 года назад

Уязвимостей на страницу