Skip to content

Commit

Permalink
NVD Sync 2024-11-29 04:12
Browse files Browse the repository at this point in the history
  • Loading branch information
github-actions[bot] committed Nov 29, 2024
1 parent 53fa3f6 commit 96a85ed
Show file tree
Hide file tree
Showing 3 changed files with 3 additions and 1 deletion.
1 change: 1 addition & 0 deletions cve/2024/CVE-2024-11978.json
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
{"cve": {"id": "CVE-2024-11978", "sourceIdentifier": "[email protected]", "published": "2024-11-29T03:15:14.700", "lastModified": "2024-11-29T03:15:14.700", "vulnStatus": "Received", "cveTags": [], "descriptions": [{"lang": "en", "value": "DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files."}], "metrics": {"cvssMetricV31": [{"source": "[email protected]", "type": "Primary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "baseScore": 7.5, "baseSeverity": "HIGH", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE"}, "exploitabilityScore": 3.9, "impactScore": 3.6}]}, "weaknesses": [{"source": "[email protected]", "type": "Primary", "description": [{"lang": "en", "value": "CWE-36"}]}], "references": [{"url": "https://www.twcert.org.tw/en/cp-139-8270-a56e6-2.html", "source": "[email protected]"}, {"url": "https://www.twcert.org.tw/tw/cp-132-8269-22a8f-1.html", "source": "[email protected]"}]}}
1 change: 1 addition & 0 deletions cve/2024/CVE-2024-11979.json
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
{"cve": {"id": "CVE-2024-11979", "sourceIdentifier": "[email protected]", "published": "2024-11-29T03:15:15.653", "lastModified": "2024-11-29T03:15:15.653", "vulnStatus": "Received", "cveTags": [], "descriptions": [{"lang": "en", "value": "DreamMaker from Interinfo has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells."}], "metrics": {"cvssMetricV31": [{"source": "[email protected]", "type": "Primary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH"}, "exploitabilityScore": 3.9, "impactScore": 5.9}]}, "weaknesses": [{"source": "[email protected]", "type": "Primary", "description": [{"lang": "en", "value": "CWE-434"}]}], "references": [{"url": "https://www.twcert.org.tw/en/cp-139-8272-13a13-2.html", "source": "[email protected]"}, {"url": "https://www.twcert.org.tw/tw/cp-132-8271-29871-1.html", "source": "[email protected]"}]}}
2 changes: 1 addition & 1 deletion syncdate.json
Original file line number Diff line number Diff line change
@@ -1 +1 @@
{"lastModStartDate": "2024-11-29T00:04:53.609716+00:00", "lastModEndDate": "2024-11-29T02:28:45.392193+00:00"}
{"lastModStartDate": "2024-11-29T02:28:45.392193+00:00", "lastModEndDate": "2024-11-29T04:03:24.370518+00:00"}

0 comments on commit 96a85ed

Please sign in to comment.