PT-2016-7213 · Exponent · Exponent Cms

Balisong

·

Publicado

2016-11-03

·

Atualizado

2018-02-27

·

CVE-2016-7095

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Exponent CMS versions prior to 2.3.9
Description The issue allows an attacker to upload a malicious script file using redirection, placing the script in an unprotected folder that permits script execution.
Recommendations For versions prior to 2.3.9, update to version 2.3.9 or later to resolve the issue.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-7095

Produtos afetados

Exponent Cms