Описание
SoftVibe SARABAN for INFOMA 1.1 allows Unauthenticated unrestricted File Upload, that allows attackers to upload files with any file extension which can lead to arbitrary code execution.
Ссылки
- Product
- ExploitThird Party AdvisoryURL Repurposed
- Product
- ExploitThird Party Advisory
- Product
- ExploitThird Party AdvisoryURL Repurposed
- Product
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:softvibe:saraban:1.1:*:*:*:*:infoma:*:*
EPSS
Процентиль: 81%
0.01555
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-434
Связанные уязвимости
CVSS3: 9.8
github
около 4 лет назад
SoftVibe SARABAN for INFOMA 1.1 allows Unauthenticated unrestricted File Upload, that allows attackers to upload files with any file extension which can lead to arbitrary code execution.
EPSS
Процентиль: 81%
0.01555
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-434