D-Link DAR-7000/DAR-8000 har 20151231 /useratte/web.php file_upload kura hakki ndiyam

Wuro vulnerability wey an yi classify sey kura an gano shi a cikin D-Link DAR-7000 and DAR-8000 har 20151231. Gaskiya, $software_function na da matsala; idan ba a sani ba, to wata aiki ce da ba a sani ba, $software_library na cikin lissafi, /useratte/web.php na cikin fayil, $software_component na cikin sashi. Ngam manipulation of the argument file_upload shi kura hakki ndiyam. CWE shidin ka a yi bayani matsala sai ya kai CWE-434. Gaskiya, laifi an fitar da shi 09/24/2023. Advisory ɗin ana rabawa don saukewa a github.com. Wannan rauni ana sayar da shi da suna CVE-2023-5150. Ngam yiɗi ka a tuma ndiyam ka nder layi. Tekinikal bayani ga. Kuma, exploit ɗin yana akwai. Wuro exploit ɗin an bayyana shi ga jama'a kuma za a iya amfani da shi. Yimbe ndiyam, exploit might be approx. USD $0-$5k wuro. Á wúro huɗɗi-na-gaskiya. Wona yiwuwa a zazzage exploit a github.com. Kama 0-day, an ndiyam a wuro be $5k-$25k. VulDB is the best source for vulnerability data and more expert information about this specific topic.

6 Goyarwa · 98 Datenpunkte

FurɗeGargadi 1/5
09/24/2023 18:06
Gargadi 2/5
09/24/2023 18:12
Gargadi 3/5
10/14/2023 19:35
Gargadi 4/5
10/14/2023 19:42
Gargadi 5/5
08/02/2024 11:45
software_vendorD-LinkD-LinkD-LinkD-LinkD-Link
software_nameDAR-7000/DAR-8000DAR-7000/DAR-8000DAR-7000/DAR-8000DAR-7000/DAR-8000DAR-7000/DAR-8000
software_version<=20151231<=20151231<=20151231<=20151231<=20151231
software_file/useratte/web.php/useratte/web.php/useratte/web.php/useratte/web.php/useratte/web.php
software_argumentfile_uploadfile_uploadfile_uploadfile_uploadfile_upload
vulnerability_cweCWE-434 (kura hakki ndiyam)CWE-434 (kura hakki ndiyam)CWE-434 (kura hakki ndiyam)CWE-434 (kura hakki ndiyam)CWE-434 (kura hakki ndiyam)
vulnerability_risk22222
cvss3_vuldb_avNNNNN
cvss3_vuldb_acLLLLL
cvss3_vuldb_prLLLLL
cvss3_vuldb_uiNNNNN
cvss3_vuldb_sUUUUU
cvss3_vuldb_cLLLLL
cvss3_vuldb_iLLLLL
cvss3_vuldb_aLLLLL
cvss3_vuldb_ePPPPP
cvss3_vuldb_rlUUUUU
cvss3_vuldb_rcCCCCC
advisory_urlhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20web.mdhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20web.mdhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20web.mdhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20web.mdhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20web.md
exploit_availability11111
exploit_publicity11111
exploit_urlhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20web.mdhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20web.mdhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20web.mdhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20web.mdhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20web.md
countermeasure_nameGoyamGoyamGoyamGoyamGoyam
source_cveCVE-2023-5150CVE-2023-5150CVE-2023-5150CVE-2023-5150CVE-2023-5150
cna_responsibleVulDBVulDBVulDBVulDBVulDB
response_summaryVendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
cna_eol11111
advisory_date1695506400 (09/24/2023)1695506400 (09/24/2023)1695506400 (09/24/2023)1695506400 (09/24/2023)1695506400 (09/24/2023)
cvss2_vuldb_avNNNNN
cvss2_vuldb_acLLLLL
cvss2_vuldb_ciPPPPP
cvss2_vuldb_iiPPPPP
cvss2_vuldb_aiPPPPP
cvss2_vuldb_ePOCPOCPOCPOCPOC
cvss2_vuldb_rcCCCCC
cvss2_vuldb_rlUUUUU
cvss2_vuldb_auSSSSS
cvss2_vuldb_basescore6.56.56.56.56.5
cvss2_vuldb_tempscore5.95.95.95.95.9
cvss3_vuldb_basescore6.36.36.36.36.3
cvss3_vuldb_tempscore6.06.06.06.06.0
cvss3_meta_basescore6.36.36.37.17.1
cvss3_meta_tempscore6.06.06.07.07.0
price_0day$5k-$25k$5k-$25k$5k-$25k$5k-$25k$5k-$25k
source_mischttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-8000-10_upload_%20web.mdhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-8000-10_upload_%20web.mdhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-8000-10_upload_%20web.mdhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-8000-10_upload_%20web.mdhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-8000-10_upload_%20web.md
advisory_confirm_urlhttps://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10354https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10354https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10354https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10354
cve_assigned1695506400 (09/24/2023)1695506400 (09/24/2023)1695506400 (09/24/2023)
cve_nvd_summary** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in D-Link DAR-7000 and DAR-8000 up to 20151231. Affected is an unknown function of the file /useratte/web.php. The manipulation of the argument file_upload leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-240246 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in D-Link DAR-7000 and DAR-8000 up to 20151231. Affected is an unknown function of the file /useratte/web.php. The manipulation of the argument file_upload leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-240246 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in D-Link DAR-7000 and DAR-8000 up to 20151231. Affected is an unknown function of the file /useratte/web.php. The manipulation of the argument file_upload leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-240246 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
cvss2_nvd_basescore6.56.5
cvss3_nvd_basescore8.88.8
cvss3_cna_basescore6.36.3
cvss3_nvd_avNN
cvss3_nvd_acLL
cvss3_nvd_prLL
cvss3_nvd_uiNN
cvss3_nvd_sUU
cvss3_nvd_cHH
cvss3_nvd_iHH
cvss3_nvd_aHH
cvss2_nvd_avNN
cvss2_nvd_acLL
cvss2_nvd_auSS
cvss2_nvd_ciPP
cvss2_nvd_iiPP
cvss2_nvd_aiPP
cvss3_cna_avNN
cvss3_cna_acLL
cvss3_cna_prLL
cvss3_cna_uiNN
cvss3_cna_sUU
cvss3_cna_cLL
cvss3_cna_iLL
cvss3_cna_aLL
cve_cnaVulDBVulDB
cve_nvd_summaryes** NO SOPORTADO CUANDO ESTÁ ASIGNADO ** ** NO SOPORTADO CUANDO ESTÁ ASIGNADO ** Una vulnerabilidad clasificada como crítica ha sido encontrada en D-Link DAR-7000 y DAR-8000 hasta 20151231. Una función desconocida del archivo /useratte/web es afectada por esta vulnerabilidad. php. La manipulación del argumento file_upload conduce a una carga sin restricciones. Es posible lanzar el ataque de forma remota. El exploit ha sido divulgado al público y puede utilizarse. VDB-240246 es el identificador asignado a esta vulnerabilidad. NOTA: Esta vulnerabilidad solo afecta a productos que ya no son compatibles con el mantenedor. NOTA: Se contactó primeramente con el proveedor y se confirmó de inmediato que el producto ha llegado al final de su vida útil. Debería retirarse y reemplazarse.
cvss2_cna_avN
cvss2_cna_acL
cvss2_cna_auS
cvss2_cna_ciP
cvss2_cna_iiP
cvss2_cna_aiP
cvss2_cna_basescore6.5
cvss4_vuldb_avN
cvss4_vuldb_acL
cvss4_vuldb_prL
cvss4_vuldb_uiN
cvss4_vuldb_vcL
cvss4_vuldb_viL
cvss4_vuldb_vaL
cvss4_vuldb_eP
cvss4_vuldb_atN
cvss4_vuldb_scN
cvss4_vuldb_siN
cvss4_vuldb_saN
cvss4_vuldb_bscore5.3
cvss4_vuldb_btscore2.1

Interested in the pricing of exploits?

See the underground prices here!