Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-6234

Опубликовано: 22 нояб. 2019
Источник: nvd
CVSS3: 8
CVSS2: 6
EPSS Низкий

Описание

Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, aka "XSS File Upload."

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:eng:spagobi:*:*:*:*:*:*:*:*
Версия до 4.1 (исключая)

EPSS

Процентиль: 84%
0.02181
Низкий

8 High

CVSS3

6 Medium

CVSS2

Дефекты

CWE-434

Связанные уязвимости

github
почти 4 года назад

Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, aka "XSS File Upload."

EPSS

Процентиль: 84%
0.02181
Низкий

8 High

CVSS3

6 Medium

CVSS2

Дефекты

CWE-434