Lucene search

K
cvelistMitreCVELIST:CVE-2020-35362
HistoryDec 26, 2020 - 5:19 a.m.

CVE-2020-35362

2020-12-2605:19:10
mitre
www.cve.org
2
dext5upload
directory traversal
remote files

EPSS

0.005

Percentile

76.5%

DEXT5Upload 2.7.1262310 and earlier is affected by Directory Traversal in handler/dext5handler.jsp. This could allow remote files to be downloaded via a dext5CMD=downloadRequest action with traversal in the fileVirtualPath parameter (the attacker must provide the correct fileOrgName value).

EPSS

0.005

Percentile

76.5%

Related for CVELIST:CVE-2020-35362