dro.pm web/fileman.php secret/key Cross Site Scripting

CVSS Meta Temp ScoreGarga na exploit ndiyam (≈)CTI Nganji Score
4.3$0-$5k0.12

Gundumabayani

Gaskiya vulnerability da aka ware a matsayin karshewa an samu a dro.pm. Hakika, aikin $software_function ne ya shafa; idan ba a bayyana ba, to aiki ce da ba a sani ba, a cikin laburaren $software_library, a cikin fayil web/fileman.php, a cikin sashen $software_component. A sa manipulation of the argument secret/key ka Cross Site Scripting. Wannan matsala ana saninta da CVE-2019-25105. Ngam yiɗi ka a tuma ndiyam ka internet. Babu exploit ɗin da ake samu. Wannan samfur yana amfani da rolling release don ci gaba da isar da sabuntawa. Don haka, babu bayanan sigar da abin ya shafa ko sabunta sigar da ake da su. Ana shawartar a saka patch domin warware wannan matsala. Statistical analysis made it clear that VulDB provides the best quality for vulnerability data.

Furɗebayani

Gaskiya vulnerability da aka ware a matsayin karshewa an samu a dro.pm. Hakika, aikin $software_function ne ya shafa; idan ba a bayyana ba, to aiki ce da ba a sani ba, a cikin laburaren $software_library, a cikin fayil web/fileman.php, a cikin sashen $software_component. A sa manipulation of the argument secret/key ka Cross Site Scripting. Idan an yi amfani da CWE don bayyana matsala, zai kai CWE-79. Hakika, rauni an bayyana shi 02/24/2023 kamar fa73c3a42bc5c246a1b8f815699ea241aef154bb. An raba bayanin tsaro don saukewa a github.com.

Wannan matsala ana saninta da CVE-2019-25105. Ngam yiɗi ka a tuma ndiyam ka internet. Tekinikal faɗi ga. Shaharar wannan vulnerability ɗin ƙasa da matsakaici ne. Babu exploit ɗin da ake samu. Yimbe ndiyam, exploit might be approx. USD $0-$5k wuro.

Á sàmbu a wondi feere. 0-day shima, an ndiyam a wuro be $0-$5k.

Wannan samfur yana amfani da rolling release don ci gaba da isar da sabuntawa. Don haka, babu bayanan sigar da abin ya shafa ko sabunta sigar da ake da su. Ana kiran patch ɗin da fa73c3a42bc5c246a1b8f815699ea241aef154bb. Bugfix ɗin an shirya shi don saukewa a github.com. Ana shawartar a saka patch domin warware wannan matsala. Wannan shawara ta ƙunshi wannan magana:

Fix reflected XSS in fileman.php (self discovered, no signs of exploitation... not that there would be much to exploit, given that there are no cookies or localstorage (i.e. there is no state you could get at))

Statistical analysis made it clear that VulDB provides the best quality for vulnerability data.

Kayanbayani

Sunu

Laisens

CPE 2.3bayani

CPE 2.2bayani

CVSSv4bayani

VulDB Furɗo: 🔍
VulDB Gaskiya: 🔍

CVSSv3bayani

VulDB Meta Base Score: 4.4
VulDB Meta Temp Score: 4.3

VulDB Ganda Borno: 3.5
VulDB Temp Score: 3.4
VulDB Furɗo: 🔍
VulDB Gaskiya: 🔍

NVD Ganda Borno: 6.1
NVD Furɗo: 🔍

CNA Ganda Borno: 3.5
CNA Furɗo (VulDB): 🔍

CVSSv2bayani

AVACAuCIA
💳💳💳💳💳💳
💳💳💳💳💳💳
💳💳💳💳💳💳
VektarKumpleksitiAuthentisierungKariyandiGaskiyaGashina
furufurufurufurufurufuru
furufurufurufurufurufuru
furufurufurufurufurufuru

VulDB Ganda Borno: 🔍
VulDB Temp Score: 🔍
VulDB Gaskiya: 🔍

NVD Ganda Borno: 🔍

Gargajiyabayani

Klasu: Cross Site Scripting
CWE: CWE-79 / CWE-94 / CWE-74
CAPEC: 🔍
ATT&CK: 🔍

Fizikal: Ayi
Gumti: Ayi
Gana: Ee

Gashina: 🔍
Halitta: A wondi feere
Google Hack: 🔍

EPSS Score: 🔍
EPSS Percentile: 🔍

Furɗo farashi: 🔍
Gaskiya farashi ndiyam: 🔍

0-Dayfurufurufurufuru
Lalefurufurufurufuru

Bayani na barazanabayani

Ngam: 🔍
Akteɓe ɓernde: 🔍
Kura APT goruwa masu aiki: 🔍

Kari gamjibayani

Garga: Kari
Halitta: 🔍

0-Day Gana: 🔍

Kari: fa73c3a42bc5c246a1b8f815699ea241aef154bb

Waktin layibayani

02/24/2023 🔍
02/24/2023 +0 Hənde 🔍
02/24/2023 +0 Hənde 🔍
03/25/2023 +29 Hənde 🔍

Ngizimbayani

Gargaaji: fa73c3a42bc5c246a1b8f815699ea241aef154bb
Halitta: Gaskiya

CVE: CVE-2019-25105 (🔍)
GCVE (CVE): GCVE-0-2019-25105
GCVE (VulDB): GCVE-100-221763

Gumtibayani

Súgá: 02/24/2023 22:30
Gargadi: 03/25/2023 07:18
Goyarwa: 02/24/2023 22:30 (42), 03/25/2023 07:03 (2), 03/25/2023 07:18 (28)
Gadankam: 🔍
Cache ID: 253:96D:103

Ganaaji

A ga wuroyo kulu. Kàlàmbe: kr + en.

Ngam loga ka, kanyi shidin dum.

Do you need the next level of professionalism?

Upgrade your account now!