PT-2019-12286 · Siteserver · Siteserver Cms
Diy0829
·
Published
2019-04-21
·
Updated
2022-05-24
·
CVE-2019-11401
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SiteServer CMS versions 6.9.0 through 6.11
Description
A issue was discovered in SiteServer CMS that allows remote attackers to execute arbitrary code. This is possible because an administrator can add the permitted file extension
.aassp, which is converted to .asp due to the deletion of the "as" substring.Recommendations
For SiteServer CMS versions 6.9.0 through 6.11, update to version 6.12 or later to resolve the issue.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Siteserver Cms