PT-2017-19097 · Alc · Sitescan Web+2
Gjoko Krstic
+1
·
Published
2017-08-25
·
Updated
2021-07-27
·
CVE-2017-9650
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ALC WebCTRL, i-Vu, SiteScan Web versions 5.2 through 6.5
ALC WebCTRL, SiteScan Web versions 6.1 and prior
ALC WebCTRL, i-Vu versions 6.0 and prior
Description
An Unrestricted Upload of File with Dangerous Type issue allows an authenticated attacker to upload a malicious file, potentially enabling the execution of arbitrary code.
Recommendations
For ALC WebCTRL, i-Vu, SiteScan Web versions 5.2 through 6.5, restrict file upload capabilities to prevent malicious file uploads until a fix is available.
For ALC WebCTRL, SiteScan Web versions 6.1 and prior, consider disabling file upload features to minimize the risk of exploitation.
For ALC WebCTRL, i-Vu versions 6.0 and prior, avoid using file upload functionality in the affected software until the issue is resolved.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alc Webctrl
Sitescan Web
I-Vu