WordPress: Unauthenticated path traversal leading to conditional RCE
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
WordPress: Unauthenticated path traversal leading to conditional RCE
Unofficial Hacker News client; not affiliated with Y Combinator.
tptacek · · focus · HN ↗
paulez · · focus · HN ↗
tptacek · · focus · HN ↗
nicce · · focus · HN ↗
Not really. They are very good at describing the technical impact. Sometimes pre-condition is very rare and that reduces overall likelihood but for those few it applies, the impact still could be catastrophic. Who wants to risk it if whole business could go down?
akerl_ · · focus · HN ↗
cleansy · · focus · HN ↗
vntok · · focus · HN ↗
Many GUI CVSS calculators exist just for this, it takes a minute to requalify a vuln and adjust its CVSS based on your specific environment.
This one for example is pretty basic but works well: <a href="https://www.first.org/cvss/calculator/4.0" rel="nofollow">https://www.first.org/cvss/calculator/4.0
> These metrics enable the analyst to customize the CVSS score depending on the importance of the affected IT asset to a user’s organization, measured in terms of complementary/alternative security controls in place, Confidentiality, Integrity, and Availability. The metrics are the modified equivalent of base metrics and are assigned metric values based on the component placement in organization infrastructure.