CyberSec.Space Logo
返回 CVE 浏览器

CVE-2018-6651

HIGH
8.8
CVSS Severity Score
EPSS Score0.0860%
EPSS Percentile20.00th
Published2018年2月5日
Last Modified2024年11月21日

Vulnerability Description

In the uncurl_ws_accept function in uncurl.c in uncurl before 0.07, as used in Parsec before 140-3, insufficient Origin header validation (accepting an arbitrary substring match) for WebSocket API requests allows remote attackers to bypass intended access restrictions. In Parsec, this means full control over the victim's computer.

Affected Platforms (CPE)

📦
Uncurl Project

Uncurl

< 0.07
📦
Parsecgaming

Parsec

< 140-3

References & Advisories

相关漏洞威胁