CVE-2017-9650

An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to upload a malicious file allowing the execution of arbitrary code.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
icscertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
VendorProductVersion
automatedlogici-vu
𝑥
≤ 5.2
automatedlogici-vu
𝑥
≤ 5.5
automatedlogici-vu
𝑥
≤ 6.0
automatedlogici-vu
𝑥
≤ 6.5
automatedlogicsitescan_web
𝑥
≤ 5.2
automatedlogicsitescan_web
𝑥
≤ 5.5
automatedlogicsitescan_web
𝑥
≤ 6.1
automatedlogicsitescan_web
𝑥
≤ 6.5
carrierautomatedlogic_webctrl
𝑥
≤ 5.2
carrierautomatedlogic_webctrl
𝑥
≤ 5.5
carrierautomatedlogic_webctrl
𝑥
≤ 6.0
carrierautomatedlogic_webctrl
𝑥
≤ 6.1
carrierautomatedlogic_webctrl
𝑥
≤ 6.5
𝑥
= Vulnerable software versions