9.8
CVE-2016-7443
- EPSS 0.89%
- Veröffentlicht 07.03.2018 02:29:00
- Zuletzt bearbeitet 21.11.2024 02:58:01
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong location."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Exponentcms ≫ Exponent Cms Version >= 2.3.0 <= 2.3.9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.89% | 0.746 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.