PT-2017-19097 · Alc · Sitescan Web+2

Gjoko Krstic

+1

·

Published

2017-08-25

·

Updated

2021-07-27

·

CVE-2017-9650

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ALC WebCTRL, i-Vu, SiteScan Web versions 5.2 through 6.5 ALC WebCTRL, SiteScan Web versions 6.1 and prior ALC WebCTRL, i-Vu versions 6.0 and prior
Description An Unrestricted Upload of File with Dangerous Type issue allows an authenticated attacker to upload a malicious file, potentially enabling the execution of arbitrary code.
Recommendations For ALC WebCTRL, i-Vu, SiteScan Web versions 5.2 through 6.5, restrict file upload capabilities to prevent malicious file uploads until a fix is available. For ALC WebCTRL, SiteScan Web versions 6.1 and prior, consider disabling file upload features to minimize the risk of exploitation. For ALC WebCTRL, i-Vu versions 6.0 and prior, avoid using file upload functionality in the affected software until the issue is resolved.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-9650

Affected Products

Alc Webctrl
Sitescan Web
I-Vu