Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-14771

Опубликовано: 03 окт. 2017
Источник: nvd
CVSS3: 5.5
CVSS2: 3.6
EPSS Низкий

Описание

Skybox Manager Client Application prior to 8.5.501 is prone to an arbitrary file upload vulnerability due to insufficient input validation of user-supplied files path when uploading files via the application. During a debugger-pause state, a local authenticated attacker can upload an arbitrary file and overwrite existing files within the scope of the affected application.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:skyboxsecurity:skybox_manager_client_application:*:*:*:*:*:*:*:*
Версия до 8.5.500 (включая)

EPSS

Процентиль: 32%
0.00124
Низкий

5.5 Medium

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.5
github
около 3 лет назад

Skybox Manager Client Application prior to 8.5.501 is prone to an arbitrary file upload vulnerability due to insufficient input validation of user-supplied files path when uploading files via the application. During a debugger-pause state, a local authenticated attacker can upload an arbitrary file and overwrite existing files within the scope of the affected application.

EPSS

Процентиль: 32%
0.00124
Низкий

5.5 Medium

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-20