CVE-2018-1306
27.06.2018, 18:29
The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict path information provided during a file upload. An attacker could exploit this vulnerability to obtain configuration data and other sensitive information.Enginsight
Vendor | Product | Version |
---|---|---|
apache | pluto | 3.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration