메뉴 건너뛰기

GREATUSER

cve

CVE-2017-16604

관리자 2018.01.25 04:00 조회 수 : 196

This vulnerability allows remote attackers to overwrite arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.cnnic.asset.deviceReport.deviceReport_005fexport_005fdo_jsp servlet, which listens on TCP port 8081 by default. When parsing the filename parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to overwrite any files accessible to the Administrator. Was ZDI-CAN-5195.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-16604
번호 제목 글쓴이 날짜 조회 수
467 CVE-2018-6002 관리자 2018.01.25 132
466 CVE-2017-7400 관리자 2017.04.04 133
465 CVE-2016-5816 관리자 2017.08.27 133
464 CVE-2017-16545 (graphicsmagick) 관리자 2017.11.09 133
463 CVE-2017-0045 관리자 2017.03.18 134
462 CVE-2017-0042 관리자 2017.03.18 134
461 CVE-2017-0122 관리자 2017.03.18 134
460 CVE-2017-7397 관리자 2017.04.04 134
459 CVE-2017-13132 (imagemagick) 관리자 2017.08.27 134
458 CVE-2015-7257 관리자 2017.08.27 134
457 CVE-2017-15672 관리자 2017.11.09 135
456 CVE-2017-0109 관리자 2017.03.18 136
455 CVE-2017-12965 (apache2triad) 관리자 2017.08.27 136
454 CVE-2017-13686 관리자 2017.08.27 136
453 CVE-2017-0079 관리자 2017.03.18 137
위로