Логотип exploitDog
bind:CVE-2018-6409
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-6409

Количество 2

Количество 2

nvd логотип

CVE-2018-6409

больше 7 лет назад

An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path from the database. Modifying the name of the file to serve on the corresponding ap_form table leads to a path traversal vulnerability via the download.php q parameter.

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-7m97-g8f2-fj9g

больше 3 лет назад

An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path from the database. Modifying the name of the file to serve on the corresponding ap_form table leads to a path traversal vulnerability via the download.php q parameter.

CVSS3: 5.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-6409

An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path from the database. Modifying the name of the file to serve on the corresponding ap_form table leads to a path traversal vulnerability via the download.php q parameter.

CVSS3: 5.3
13%
Средний
больше 7 лет назад
github логотип
GHSA-7m97-g8f2-fj9g

An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path from the database. Modifying the name of the file to serve on the corresponding ap_form table leads to a path traversal vulnerability via the download.php q parameter.

CVSS3: 5.3
13%
Средний
больше 3 лет назад

Уязвимостей на страницу