Описание
O'Reilly WebSite Pro 2.3.7 installs the uploader.exe program with execute permissions for all users, which allows remote attackers to create and execute arbitrary files by directly calling uploader.exe.
Ссылки
- PatchVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.3.7 (включая)
cpe:2.3:a:oreilly:website_pro:*:*:*:*:*:*:*:*
EPSS
Процентиль: 68%
0.00569
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
O'Reilly WebSite Pro 2.3.7 installs the uploader.exe program with execute permissions for all users, which allows remote attackers to create and execute arbitrary files by directly calling uploader.exe.
EPSS
Процентиль: 68%
0.00569
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other