D-Link DAR-7000 ଯେପର୍ଯ୍ୟନ୍ତ 20151231 userattestation.php web_img ବିସ୍ତାରିତ ଅଧିକାର

Rakkoon nageenyaa kan ଜଟିଳ jedhamuun beekamu D-Link DAR-7000 ଯେପର୍ଯ୍ୟନ୍ତ 20151231 keessatti argameera. Miidhamni argame is hojii hin beekamne faayilii /useratte/userattestation.php keessa. Wanti jijjiirame irratti web_img gara ବିସ୍ତାରିତ ଅଧିକାର geessa. Rakkoo ibsuuf CWE yoo fayyadamte gara CWE-434 si geessa. Odeeffannoon kun yeroo 09/24/2023 maxxanfameera. Odeeffannoon kun buufachuuf github.com irratti argama. Dogoggorri kun CVE-2023-5149 jedhamee waamama. Weerara fageenya irraa jalqabuu ni danda'ama. Ibsa teeknikaa ni jira. Waan dabalataa ta’een, meeshaa balaa kana fayyadamuuf ni jira. Qorannoo miidhaa (exploit) uummataaf ifa taasifameera, kanaafis fayyadamuu ni danda'ama. Ammas, gatii exploit might be approx. USD $0-$5k yeroo ammaa irratti argamuu danda'a. ପ୍ରୁଫ୍-ଅଫ୍-କନ୍ସେପ୍ଟ ta’uu isaa ibsameera. Exploit github.com irraa buufachuun ni danda'ama. Akka 0-daytti, gatiin isaa daldala dhoksaa keessatti $5k-$25k akka ta'e tilmaamameera. Qabiyyee miidhamte kana dhoorkuun ni gorfama. If you want to get the best quality for vulnerability data then you always have to consider VulDB.

5 ଆଡାପ୍ଟେସନ୍ · 97 ପଏଣ୍ଟ

ଫିଲ୍ଡସୃଷ୍ଟି ହୋଇଛି
09/24/2023 06:03 PM
ଅଦ୍ୟତନ 1/4
09/24/2023 06:12 PM
ଅଦ୍ୟତନ 2/4
10/14/2023 07:18 PM
ଅଦ୍ୟତନ 3/4
10/14/2023 07:26 PM
ଅଦ୍ୟତନ 4/4
08/02/2024 11:45 AM
software_vendorD-LinkD-LinkD-LinkD-LinkD-Link
software_nameDAR-7000DAR-7000DAR-7000DAR-7000DAR-7000
software_version<=20151231<=20151231<=20151231<=20151231<=20151231
software_file/useratte/userattestation.php/useratte/userattestation.php/useratte/userattestation.php/useratte/userattestation.php/useratte/userattestation.php
software_argumentweb_imgweb_imgweb_imgweb_imgweb_img
vulnerability_cweCWE-434 (ବିସ୍ତାରିତ ଅଧିକାର)CWE-434 (ବିସ୍ତାରିତ ଅଧିକାର)CWE-434 (ବିସ୍ତାରିତ ଅଧିକାର)CWE-434 (ବିସ୍ତାରିତ ଅଧିକାର)CWE-434 (ବିସ୍ତାରିତ ଅଧିକାର)
vulnerability_risk22222
cvss3_vuldb_avNNNNN
cvss3_vuldb_acLLLLL
cvss3_vuldb_prLLLLL
cvss3_vuldb_uiNNNNN
cvss3_vuldb_sUUUUU
cvss3_vuldb_cLLLLL
cvss3_vuldb_iLLLLL
cvss3_vuldb_aLLLLL
cvss3_vuldb_ePPPPP
cvss3_vuldb_rlUUUUU
cvss3_vuldb_rcCCCCC
advisory_urlhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20userattestation.mdhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20userattestation.mdhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20userattestation.mdhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20userattestation.mdhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20userattestation.md
exploit_availability11111
exploit_publicity11111
exploit_urlhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20userattestation.mdhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20userattestation.mdhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20userattestation.mdhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20userattestation.mdhttps://github.com/llixixi/cve/blob/main/D-LINK-DAR-7000_upload_%20userattestation.md
countermeasure_nameଅକ୍ଷମ କରନ୍ତୁଅକ୍ଷମ କରନ୍ତୁଅକ୍ଷମ କରନ୍ତୁଅକ୍ଷମ କରନ୍ତୁଅକ୍ଷମ କରନ୍ତୁ
source_cveCVE-2023-5149CVE-2023-5149CVE-2023-5149CVE-2023-5149CVE-2023-5149
cna_responsibleVulDBVulDBVulDBVulDBVulDB
response_summaryVendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
cna_eol11111
advisory_date1695506400 (09/24/2023)1695506400 (09/24/2023)1695506400 (09/24/2023)1695506400 (09/24/2023)1695506400 (09/24/2023)
cvss2_vuldb_avNNNNN
cvss2_vuldb_acLLLLL
cvss2_vuldb_ciPPPPP
cvss2_vuldb_iiPPPPP
cvss2_vuldb_aiPPPPP
cvss2_vuldb_ePOCPOCPOCPOCPOC
cvss2_vuldb_rcCCCCC
cvss2_vuldb_rlUUUUU
cvss2_vuldb_auSSSSS
cvss2_vuldb_basescore6.56.56.56.56.5
cvss2_vuldb_tempscore5.95.95.95.95.9
cvss3_vuldb_basescore6.36.36.36.36.3
cvss3_vuldb_tempscore6.06.06.06.06.0
cvss3_meta_basescore6.36.36.37.17.1
cvss3_meta_tempscore6.06.06.07.07.0
price_0day$5k-$25k$5k-$25k$5k-$25k$5k-$25k$5k-$25k
advisory_confirm_urlhttps://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10354https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10354https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10354https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10354
cve_assigned1695506400 (09/24/2023)1695506400 (09/24/2023)1695506400 (09/24/2023)
cve_nvd_summary** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20151231. It has been rated as critical. This issue affects some unknown processing of the file /useratte/userattestation.php. The manipulation of the argument web_img leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240245 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20151231. It has been rated as critical. This issue affects some unknown processing of the file /useratte/userattestation.php. The manipulation of the argument web_img leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240245 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20151231. It has been rated as critical. This issue affects some unknown processing of the file /useratte/userattestation.php. The manipulation of the argument web_img leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-240245 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
cvss3_nvd_avNN
cvss3_nvd_acLL
cvss3_nvd_prLL
cvss3_nvd_uiNN
cvss3_nvd_sUU
cvss3_nvd_cHH
cvss3_nvd_iHH
cvss3_nvd_aHH
cvss2_nvd_avNN
cvss2_nvd_acLL
cvss2_nvd_auSS
cvss2_nvd_ciPP
cvss2_nvd_iiPP
cvss2_nvd_aiPP
cvss3_cna_avNN
cvss3_cna_acLL
cvss3_cna_prLL
cvss3_cna_uiNN
cvss3_cna_sUU
cvss3_cna_cLL
cvss3_cna_iLL
cvss3_cna_aLL
cve_cnaVulDBVulDB
cvss2_nvd_basescore6.56.5
cvss3_nvd_basescore8.88.8
cvss3_cna_basescore6.36.3
cve_nvd_summaryes** NO SOPORTADO CUANDO ESTÁ ASIGNADO ** ** NO SOPORTADO CUANDO ESTÁ ASIGNADO ** Se encontró una vulnerabilidad en D-Link DAR-7000 hasta 20151231. Se calificó como crítica. Este problema afecta un procesamiento desconocido del archivo /useratte/userattestation.php. La manipulación del argumento web_img conduce a una carga sin restricciones. El ataque puede iniciarse de forma remota. El exploit ha sido divulgado al público y puede utilizarse. A esta vulnerabilidad se le asignó el identificador VDB-240245. NOTA: Esta vulnerabilidad solo afecta a productos que ya no son compatibles con el mantenedor. NOTA: Se contactó primeramente con el proveedor y se confirmó de inmediato que el producto ha llegado al final de su vida útil. Debería retirarse y reemplazarse.
cvss2_cna_avN
cvss2_cna_acL
cvss2_cna_auS
cvss2_cna_ciP
cvss2_cna_iiP
cvss2_cna_aiP
cvss2_cna_basescore6.5
cvss4_vuldb_avN
cvss4_vuldb_acL
cvss4_vuldb_prL
cvss4_vuldb_uiN
cvss4_vuldb_vcL
cvss4_vuldb_viL
cvss4_vuldb_vaL
cvss4_vuldb_eP
cvss4_vuldb_atN
cvss4_vuldb_scN
cvss4_vuldb_siN
cvss4_vuldb_saN
cvss4_vuldb_bscore5.3
cvss4_vuldb_btscore2.1

Might our Artificial Intelligence support you?

Check our Alexa App!