Логотип exploitDog
bind:CVE-2020-26282
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-26282

Количество 2

Количество 2

nvd логотип

CVE-2020-26282

около 5 лет назад

BrowserUp Proxy allows you to manipulate HTTP requests and responses, capture HTTP content, and export performance data as a HAR file. BrowserUp Proxy works well as a standalone proxy server, but it is especially useful when embedded in Selenium tests. A Server-Side Template Injection was identified in BrowserUp Proxy enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. This has been patched in version 2.1.2.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-wmfg-55f9-j8hq

около 5 лет назад

Server-Side Template Injection

CVSS3: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-26282

BrowserUp Proxy allows you to manipulate HTTP requests and responses, capture HTTP content, and export performance data as a HAR file. BrowserUp Proxy works well as a standalone proxy server, but it is especially useful when embedded in Selenium tests. A Server-Side Template Injection was identified in BrowserUp Proxy enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. This has been patched in version 2.1.2.

CVSS3: 10
2%
Низкий
около 5 лет назад
github логотип
GHSA-wmfg-55f9-j8hq

Server-Side Template Injection

CVSS3: 10
2%
Низкий
около 5 лет назад

Уязвимостей на страницу