Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-3088

Опубликовано: 01 июл. 2014
Источник: nvd
CVSS2: 5.5
EPSS Низкий

Описание

stconf.nsf in IBM Sametime Meeting Server 8.5.1 relies on the client to validate the file format used in wAttach?OpenForm multipart/form-data POST requests, which allows remote authenticated users to bypass intended upload restrictions by modifying the Content-Type header and file extension, as demonstrated by replacing a text/plain .txt upload with an application/octet-stream .exe upload.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ibm:sametime_meeting_server:8.5.1:*:*:*:*:*:*:*

EPSS

Процентиль: 44%
0.00212
Низкий

5.5 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
больше 3 лет назад

stconf.nsf in IBM Sametime Meeting Server 8.5.1 relies on the client to validate the file format used in wAttach?OpenForm multipart/form-data POST requests, which allows remote authenticated users to bypass intended upload restrictions by modifying the Content-Type header and file extension, as demonstrated by replacing a text/plain .txt upload with an application/octet-stream .exe upload.

EPSS

Процентиль: 44%
0.00212
Низкий

5.5 Medium

CVSS2

Дефекты

CWE-264