CVE-2012-1195
18.02.2012, 00:55
Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via a PutUpdateFileCore command in a RunAMTCommand SOAP request, then accessing the file via a direct request to the file in the web root.Enginsight
Vendor | Product | Version |
---|---|---|
landesk | lenovo_thinkmanagement_console | 9.0.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References