CVE-2014-5468
07.02.2020, 17:15
A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cfm to specify a malicious PNG file, which could let a remote malicious user obtain sensitive information or execute arbitrary code.Enginsight
Vendor | Product | Version |
---|---|---|
getrailo | railo | 𝑥 ≤ 4.2.1.000 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References