Логотип exploitDog
bind:CVE-2023-6038
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-6038

Количество 2

Количество 2

nvd логотип

CVE-2023-6038

около 2 лет назад

A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the server with the permissions of the user running the h2o-3 instance. This issue affects the default installation and does not require user interaction. The vulnerability can be exploited by making specific GET or POST requests to the ImportFiles and ParseSetup endpoints, respectively. This issue was identified in version 3.40.0.4 of h2o-3.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-6mv8-95x5-xcq9

около 2 лет назад

H2O local file inclusion vulnerability

CVSS3: 9.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-6038

A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the server with the permissions of the user running the h2o-3 instance. This issue affects the default installation and does not require user interaction. The vulnerability can be exploited by making specific GET or POST requests to the ImportFiles and ParseSetup endpoints, respectively. This issue was identified in version 3.40.0.4 of h2o-3.

CVSS3: 7.5
63%
Средний
около 2 лет назад
github логотип
GHSA-6mv8-95x5-xcq9

H2O local file inclusion vulnerability

CVSS3: 9.3
63%
Средний
около 2 лет назад

Уязвимостей на страницу