PT-2012-2047 · Sit! · Support Incident Tracker
Publicado
2012-01-29
·
Atualizado
2017-08-29
·
CVE-2011-5069
CVSS v2.0
6.0
Média
| Vetor | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Support Incident Tracker (aka SiT!) version 3.65
Description
The issue allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension to the
incident attachments.php file, and then accessing it via a direct request.Recommendations
For version 3.65, consider restricting access to the
incident attachments.php file to prevent unauthorized file uploads until a patch is available. As a temporary workaround, restrict the ability to upload files with executable extensions to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Support Incident Tracker