PT-2017-19091 · Alc · Sitescan Web+2
Gjoko Krstic
+1
·
Publicado
2017-08-25
·
Atualizado
2021-07-27
·
CVE-2017-9644
CVSS v3.1
7.0
Alta
| Vetor | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ALC WebCTRL, i-Vu, SiteScan Web versions 5.2 through 6.5
ALC WebCTRL, SiteScan Web versions 6.1 and prior
ALC WebCTRL, i-Vu versions 6.0 and prior
Description
An Unquoted Search Path or Element issue may allow a non-privileged local attacker to change files in the installation directory and execute arbitrary code with elevated privileges.
Recommendations
For ALC WebCTRL, i-Vu, SiteScan Web versions 5.2 through 6.5, update to a version later than 6.5 to resolve the issue.
For ALC WebCTRL, SiteScan Web versions 6.1 and prior, update to a version later than 6.1 to resolve the issue.
For ALC WebCTRL, i-Vu versions 6.0 and prior, update to a version later than 6.0 to resolve the issue.
As a temporary workaround, consider restricting access to the installation directory to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alc Webctrl
Sitescan Web
I-Vu