CVE-2017-5539 - CERT CVE
ID CVE-2017-5539
Sažetak The patch for directory traversal (CVE-2017-5480) in b2evolution version 6.8.4-stable has a bypass vulnerability. An attacker can use ..\/ to bypass the filter rule. Then, this attacker can exploit this vulnerability to delete or read any files on the server. It can also be used to determine whether a file exists.
Reference
CVSS
Base: 9.0
Impact: 8.5
Exploitability:10.0
Pristup
VektorSloženostAutentikacija
NETWORK LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
COMPLETE PARTIAL PARTIAL
CVSS vektor AV:N/AC:L/Au:N/C:C/I:P/A:P
Zadnje važnije ažuriranje 03-10-2019 - 00:03
Objavljeno 23-01-2017 - 07:59