Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-10054

Опубликовано: 13 авг. 2025
Источник: nvd
CVSS3: 9.8
EPSS Высокий

Описание

Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a SaveDLRScript operation that permits arbitrary file uploads without authentication. By exploiting a path traversal flaw in the fileName parameter, attackers can write malicious ASPX scripts directly into the web-accessible /umbraco/ directory and execute them remotely.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:umbraco:umbraco_cms:*:*:*:*:*:*:*:*
Версия до 4.7.1 (исключая)

EPSS

Процентиль: 99%
0.75944
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-22
CWE-434

Связанные уязвимости

CVSS3: 9.8
github
6 месяцев назад

Umbraco CMS versions prior to 4.7.1 are vulnerable to unauthenticated remote code execution via the codeEditorSave.asmx SOAP endpoint, which exposes a SaveDLRScript operation that permits arbitrary file uploads without authentication. By exploiting a path traversal flaw in the fileName parameter, attackers can write malicious ASPX scripts directly into the web-accessible /umbraco/ directory and execute them remotely.

EPSS

Процентиль: 99%
0.75944
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-22
CWE-434