PT-2017-19091 · Alc · Sitescan Web+2

Gjoko Krstic

+1

·

Publicado

2017-08-25

·

Atualizado

2021-07-27

·

CVE-2017-9644

CVSS v3.1

7.0

Alta

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ALC WebCTRL, i-Vu, SiteScan Web versions 5.2 through 6.5 ALC WebCTRL, SiteScan Web versions 6.1 and prior ALC WebCTRL, i-Vu versions 6.0 and prior
Description An Unquoted Search Path or Element issue may allow a non-privileged local attacker to change files in the installation directory and execute arbitrary code with elevated privileges.
Recommendations For ALC WebCTRL, i-Vu, SiteScan Web versions 5.2 through 6.5, update to a version later than 6.5 to resolve the issue. For ALC WebCTRL, SiteScan Web versions 6.1 and prior, update to a version later than 6.1 to resolve the issue. For ALC WebCTRL, i-Vu versions 6.0 and prior, update to a version later than 6.0 to resolve the issue. As a temporary workaround, consider restricting access to the installation directory to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-9644

Produtos afetados

Alc Webctrl
Sitescan Web
I-Vu