CVE-2017-9602
16.06.2017, 13:29
KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component. An unauthenticated user can access the file upload and deletion functionality. Through this functionality, a user can upload an ASPX script to Uploads/Documents/ to run any arbitrary code.Enginsight
Vendor | Product | Version |
---|---|---|
kbvault_mysql_project | kbvault_mysql | 0.16a:a |
𝑥
= Vulnerable software versions
Common Weakness Enumeration