PT-2017-19097 · Alc · Sitescan Web+2
Gjoko Krstic
+1
·
Publicado
2017-08-25
·
Atualizado
2021-07-27
·
CVE-2017-9650
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ALC WebCTRL, i-Vu, SiteScan Web versions 5.2 through 6.5
ALC WebCTRL, SiteScan Web versions 6.1 and prior
ALC WebCTRL, i-Vu versions 6.0 and prior
Description
An Unrestricted Upload of File with Dangerous Type issue allows an authenticated attacker to upload a malicious file, potentially enabling the execution of arbitrary code.
Recommendations
For ALC WebCTRL, i-Vu, SiteScan Web versions 5.2 through 6.5, restrict file upload capabilities to prevent malicious file uploads until a fix is available.
For ALC WebCTRL, SiteScan Web versions 6.1 and prior, consider disabling file upload features to minimize the risk of exploitation.
For ALC WebCTRL, i-Vu versions 6.0 and prior, avoid using file upload functionality in the affected software until the issue is resolved.
Exploit
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alc Webctrl
Sitescan Web
I-Vu