PT-2016-1121 · Advantech · Webaccess

Aleksey Osipov

+1

·

Publicado

2016-01-15

·

Atualizado

2016-12-03

·

CVE-2016-0854

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advantech WebAccess versions prior to 8.1
Description The issue is related to an unrestricted file upload vulnerability. This vulnerability can be exploited by a remote attacker to modify files of any type. The vulnerability is associated with the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer.
Recommendations For versions prior to 8.1, update to version 8.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the uploadImageCommon function in the UploadAjaxAction script until a patch is available. Restrict access to the UploadAjaxAction script to minimize the risk of exploitation.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00380
CVE-2016-0854
ZDI-16-127
ZDI-16-128
ZDI-16-129

Produtos afetados

Webaccess