메뉴 건너뛰기

GREATUSER

cve

CVE-2017-16610

관리자 2018.01.25 04:00 조회 수 : 173

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within upload_save_do.jsp. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code under the context of the current user. Was ZDI-CAN-4751.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-16610
번호 제목 글쓴이 날짜 조회 수
452 CVE-2015-3257 관리자 2017.08.27 137
451 CVE-2017-2865 관리자 2017.11.09 137
450 CVE-2017-2922 관리자 2017.11.09 137
449 CVE-2018-6029 관리자 2018.01.25 137
448 CVE-2017-12809 (qemu) 관리자 2017.08.27 138
447 CVE-2014-7859 관리자 2017.08.27 138
446 CVE-2017-15107 관리자 2018.01.25 138
445 CVE-2017-16565 관리자 2017.11.09 139
444 CVE-2017-2912 관리자 2017.11.09 139
443 CVE-2017-14096 관리자 2018.01.25 139
442 CVE-2017-18045 관리자 2018.01.25 139
441 CVE-2016-6992 관리자 2016.10.14 140
440 CVE-2017-0095 관리자 2017.03.18 140
439 CVE-2018-6001 관리자 2018.01.25 141
438 CVE-2014-3927 관리자 2017.04.04 142
위로