Логотип exploitDog
bind:CVE-2022-44006
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-44006

Количество 2

Количество 2

nvd логотип

CVE-2022-44006

около 3 лет назад

An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, unauthenticated update function permits writing files outside the intended target location. Achieving remote code execution is possible, e.g., by uploading an executable file.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-v352-9jvg-8c8q

около 3 лет назад

An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, unauthenticated update function permits writing files outside the intended target location. Achieving remote code execution is possible, e.g., by uploading an executable file.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-44006

An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, unauthenticated update function permits writing files outside the intended target location. Achieving remote code execution is possible, e.g., by uploading an executable file.

CVSS3: 9.8
6%
Низкий
около 3 лет назад
github логотип
GHSA-v352-9jvg-8c8q

An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, unauthenticated update function permits writing files outside the intended target location. Achieving remote code execution is possible, e.g., by uploading an executable file.

CVSS3: 9.8
6%
Низкий
около 3 лет назад

Уязвимостей на страницу