Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-0678

Опубликовано: 28 янв. 2011
Источник: nvd
CVSS2: 6.8
EPSS Средний

Описание

Unrestricted file upload vulnerability in the EasyEdit module in Lomtec ActiveWeb Professional 3.0 allows remote attackers to execute arbitrary code by uploading an executable file via the UploadDirectory and Accepted Extensions fields in the getImagefile component of EasyEdit.cfm.

Комментарий

Per: http://cwe.mitre.org/data/definitions/434.html

'CWE-434: Unrestricted Upload of File with Dangerous Type'

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lomtec:activeweb:3.0:*:professional:*:*:*:*:*

EPSS

Процентиль: 96%
0.27886
Средний

6.8 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
больше 3 лет назад

Unrestricted file upload vulnerability in the EasyEdit module in Lomtec ActiveWeb Professional 3.0 allows remote attackers to execute arbitrary code by uploading an executable file via the UploadDirectory and Accepted Extensions fields in the getImagefile component of EasyEdit.cfm.

EPSS

Процентиль: 96%
0.27886
Средний

6.8 Medium

CVSS2

Дефекты

NVD-CWE-Other