메뉴 건너뛰기

GREATUSER

cve

CVE-2017-16610

관리자 2018.01.25 04:00 조회 수 : 173

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within upload_save_do.jsp. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code under the context of the current user. Was ZDI-CAN-4751.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-16610
번호 제목 글쓴이 날짜 조회 수
137 CVE-2016-10317 관리자 2017.04.04 142
136 CVE-2014-3929 관리자 2017.04.04 142
135 CVE-2014-3927 관리자 2017.04.04 142
134 CVE-2018-6001 관리자 2018.01.25 141
133 CVE-2017-0095 관리자 2017.03.18 140
132 CVE-2016-6992 관리자 2016.10.14 140
131 CVE-2017-15107 관리자 2018.01.25 139
130 CVE-2017-18045 관리자 2018.01.25 139
129 CVE-2017-14096 관리자 2018.01.25 139
128 CVE-2017-2912 관리자 2017.11.09 139
127 CVE-2017-16565 관리자 2017.11.09 139
126 CVE-2017-12809 (qemu) 관리자 2017.08.27 139
125 CVE-2014-7859 관리자 2017.08.27 138
124 CVE-2018-6029 관리자 2018.01.25 137
123 CVE-2017-2922 관리자 2017.11.09 137
위로