Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-2349

Опубликовано: 12 мая 2006
Источник: nvd
CVSS2: 6.8
EPSS Средний

Описание

E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to upload or modify arbitrary files, and execute arbitrary code, via a direct request to (1) common/html_editor/image_browser.upload.html, (2) common/html_editor/image_browser.html, or (3) common/html_editor/html_editor.html. NOTE: this can also be used for cross-site scripting (XSS) attacks by uploading cascading style sheet (.CSS) files.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:oasyssoft:e-business_designer:*:*:*:*:*:*:*:*
Версия до 3.1.4 (включая)

EPSS

Процентиль: 93%
0.10603
Средний

6.8 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to upload or modify arbitrary files, and execute arbitrary code, via a direct request to (1) common/html_editor/image_browser.upload.html, (2) common/html_editor/image_browser.html, or (3) common/html_editor/html_editor.html. NOTE: this can also be used for cross-site scripting (XSS) attacks by uploading cascading style sheet (.CSS) files.

EPSS

Процентиль: 93%
0.10603
Средний

6.8 Medium

CVSS2

Дефекты

NVD-CWE-Other