Логотип exploitDog
bind:CVE-2021-26473
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-26473

Количество 2

Количество 2

nvd логотип

CVE-2021-26473

больше 4 лет назад

In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 the http API located at /sgwebservice_o.php action logFilePath allows an attacker to write arbitrary files in the context of the web server process. These files can then be executed remotely by calling the file via the web server.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-8x7w-j66g-cfqw

больше 3 лет назад

Vembu BDR Suite before 4.2.0 allows Unauthenticated file write via a GET request that specifies a file's name and content.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-26473

In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 the http API located at /sgwebservice_o.php action logFilePath allows an attacker to write arbitrary files in the context of the web server process. These files can then be executed remotely by calling the file via the web server.

CVSS3: 9.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-8x7w-j66g-cfqw

Vembu BDR Suite before 4.2.0 allows Unauthenticated file write via a GET request that specifies a file's name and content.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу