Логотип exploitDog
bind:CVE-2020-37088
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-37088

Количество 2

Количество 2

nvd логотип

CVE-2020-37088

5 дней назад

School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' parameter in download.php. Attackers can access sensitive configuration files by supplying directory traversal paths to retrieve system credentials and configuration information.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-h3gp-whxh-7hq8

5 дней назад

School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' parameter in download.php. Attackers can access sensitive configuration files by supplying directory traversal paths to retrieve system credentials and configuration information.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-37088

School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' parameter in download.php. Attackers can access sensitive configuration files by supplying directory traversal paths to retrieve system credentials and configuration information.

CVSS3: 7.5
1%
Низкий
5 дней назад
github логотип
GHSA-h3gp-whxh-7hq8

School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'document' parameter in download.php. Attackers can access sensitive configuration files by supplying directory traversal paths to retrieve system credentials and configuration information.

CVSS3: 7.5
1%
Низкий
5 дней назад

Уязвимостей на страницу