Логотип exploitDog
bind:CVE-2020-15929
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-15929

Количество 2

Количество 2

nvd логотип

CVE-2020-15929

около 5 лет назад

In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow an attacker to write an arbitrary CFM file (within the application's context) containing attacker-defined CFML tags, leading to Remote Code Execution.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-cq82-f654-8cvc

больше 3 лет назад

In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow an attacker to write an arbitrary CFM file (within the application's context) containing attacker-defined CFML tags, leading to Remote Code Execution.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-15929

In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow an attacker to write an arbitrary CFM file (within the application's context) containing attacker-defined CFML tags, leading to Remote Code Execution.

CVSS3: 9.8
8%
Низкий
около 5 лет назад
github логотип
GHSA-cq82-f654-8cvc

In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow an attacker to write an arbitrary CFM file (within the application's context) containing attacker-defined CFML tags, leading to Remote Code Execution.

8%
Низкий
больше 3 лет назад

Уязвимостей на страницу