Логотип exploitDog
bind:CVE-2018-9148
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-9148

Количество 2

Количество 2

nvd логотип

CVE-2018-9148

почти 8 лет назад

Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass authentication by listing a directory. NOTE: this can be exploited in conjunction with CVE-2018-7171 for remote authentication bypass within a product that uses My Cloud.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-hrr3-c733-fj52

больше 3 лет назад

Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass authentication by listing a directory. NOTE: this can be exploited in conjunction with CVE-2018-7171 for remote authentication bypass within a product that uses My Cloud.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-9148

Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass authentication by listing a directory. NOTE: this can be exploited in conjunction with CVE-2018-7171 for remote authentication bypass within a product that uses My Cloud.

CVSS3: 9.8
2%
Низкий
почти 8 лет назад
github логотип
GHSA-hrr3-c733-fj52

Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass authentication by listing a directory. NOTE: this can be exploited in conjunction with CVE-2018-7171 for remote authentication bypass within a product that uses My Cloud.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу