Логотип exploitDog
bind:CVE-2022-35857
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-35857

Количество 2

Количество 2

nvd логотип

CVE-2022-35857

больше 3 лет назад

kvf-admin through 2022-02-12 allows remote attackers to execute arbitrary code because deserialization is mishandled. The rememberMe parameter is encrypted with a hardcoded key from the com.kalvin.kvf.common.shiro.ShiroConfig file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-h775-wq88-p3f2

больше 3 лет назад

kvf-admin through 2022-02-12 allows remote attackers to execute arbitrary code because deserialization is mishandled. The rememberMe parameter is encrypted with a hardcoded key from the com.kalvin.kvf.common.shiro.ShiroConfig file.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-35857

kvf-admin through 2022-02-12 allows remote attackers to execute arbitrary code because deserialization is mishandled. The rememberMe parameter is encrypted with a hardcoded key from the com.kalvin.kvf.common.shiro.ShiroConfig file.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-h775-wq88-p3f2

kvf-admin through 2022-02-12 allows remote attackers to execute arbitrary code because deserialization is mishandled. The rememberMe parameter is encrypted with a hardcoded key from the com.kalvin.kvf.common.shiro.ShiroConfig file.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу