PT-2017-19062 · Kbvault · Kbvault Mysql Free Knowledge Base

Fatih Emiral

·

Publicado

2017-06-16

·

Atualizado

2020-01-24

·

CVE-2017-9602

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions KBVault Mysql Free Knowledge Base application package version 0.16a
Description The issue allows an unauthenticated user to access file upload and deletion functionality through the FileExplorer/Explorer.aspx component. This can be exploited to upload an ASPX script to the Uploads/Documents/ directory, enabling the execution of arbitrary code.
Recommendations For version 0.16a, restrict access to the FileExplorer/Explorer.aspx?id= component to prevent unauthenticated users from uploading or deleting files, and avoid using the file upload functionality until a fix is available.

Exploit

Correção

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-9602

Produtos afetados

Kbvault Mysql Free Knowledge Base