CVE-2020-12252
29.04.2020, 14:15
An issue was discovered in Gigamon GigaVUE 5.5.01.11. The upload functionality allows an arbitrary file upload for an authenticated user. If an executable file is uploaded into the www-root directory, then it could yield remote code execution via the filename parameter.Enginsight
Vendor | Product | Version |
---|---|---|
gigamon | gigavue | 5.4 ≤ 𝑥 < 5.4.04 |
gigamon | gigavue | 5.5 ≤ 𝑥 < 5.5.02 |
gigamon | gigavue | 5.6 ≤ 𝑥 < 5.6.02 |
gigamon | gigavue | 5.7 ≤ 𝑥 < 5.7.04 |
gigamon | gigavue | 5.8 ≤ 𝑥 < 5.8.02 |
gigamon | gigavue | 5.9 ≤ 𝑥 < 5.9.00.04 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References