Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-0854

Опубликовано: 15 янв. 2016
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Высокий

Описание

Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows remote attackers to write to files of arbitrary types via unspecified vectors.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:advantech:webaccess:*:*:*:*:*:*:*:*
Версия до 8.0 (включая)

EPSS

Процентиль: 100%
0.77044
Высокий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

CVSS3: 9.8
github
около 4 лет назад

Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows remote attackers to write to files of arbitrary types via unspecified vectors.

fstec
больше 10 лет назад

Уязвимость программного обеспечения удаленного мониторинга Advantech WebAccess, позволяющая нарушителю изменять файлы любого типа

EPSS

Процентиль: 100%
0.77044
Высокий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

NVD-CWE-Other