Количество 2
Количество 2
CVE-2016-2164
The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings before 3.1.1 improperly use the Java URL class without checking the specified protocol handler, which allows remote attackers to read arbitrary files by attempting to upload a file.
GHSA-f6vf-465r-h42p
Apache OpenMeetings allows remote attackers to read arbitrary files by attempting to upload a file
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2016-2164 The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings before 3.1.1 improperly use the Java URL class without checking the specified protocol handler, which allows remote attackers to read arbitrary files by attempting to upload a file. | CVSS3: 7.5 | 1% Низкий | почти 10 лет назад | |
GHSA-f6vf-465r-h42p Apache OpenMeetings allows remote attackers to read arbitrary files by attempting to upload a file | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу