Количество 2
Количество 2
CVE-2024-33434
An issue in tiagorlampert CHAOS before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae669c481ed5e allows a remote attacker to execute arbitrary code via the unsafe concatenation of the `filename` argument into the `buildStr` string without any sanitization or filtering.
GHSA-xfjj-f699-rc79
tiagorlampert CHAOS vulnerable to arbitrary code execution
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-33434 An issue in tiagorlampert CHAOS before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae669c481ed5e allows a remote attacker to execute arbitrary code via the unsafe concatenation of the `filename` argument into the `buildStr` string without any sanitization or filtering. | CVSS3: 9.8 | 6% Низкий | почти 2 года назад | |
GHSA-xfjj-f699-rc79 tiagorlampert CHAOS vulnerable to arbitrary code execution | CVSS3: 9.8 | 6% Низкий | почти 2 года назад |
Уязвимостей на страницу