메뉴 건너뛰기

GREATUSER

cve

CVE-2017-16610

관리자 2018.01.25 04:00 조회 수 : 173

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within upload_save_do.jsp. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code under the context of the current user. Was ZDI-CAN-4751.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-16610
번호 제목 글쓴이 날짜 조회 수
437 CVE-2014-3929 관리자 2017.04.04 142
436 CVE-2016-10317 관리자 2017.04.04 142
435 CVE-2018-1045 관리자 2018.01.25 142
434 CVE-2017-6549 관리자 2017.03.10 143
433 CVE-2017-16548 관리자 2017.11.09 143
432 CVE-2017-16001 관리자 2017.11.09 143
431 CVE-2017-0091 관리자 2017.03.18 144
430 CVE-2017-2884 관리자 2017.11.09 144
429 CVE-2017-0026 관리자 2017.03.18 145
428 CVE-2017-13648 (graphicsmagick) 관리자 2017.08.27 145
427 CVE-2017-9644 관리자 2017.08.27 145
426 CVE-2017-14122 관리자 2017.09.04 145
425 CVE-2017-14094 관리자 2018.01.25 145
424 CVE-2017-6558 관리자 2017.03.10 146
423 CVE-2017-0043 관리자 2017.03.18 146
위로