This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within upload_save_do.jsp. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code under the context of the current user. Was ZDI-CAN-4751.
원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-16610
원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-16610
댓글 0
번호 | 제목 | 글쓴이 | 날짜 | 조회 수 |
---|---|---|---|---|
137 | CVE-2017-0100 | 관리자 | 2017.03.18 | 3 |
136 | CVE-2017-0088 | 관리자 | 2017.03.18 | 2 |
135 | CVE-2017-0098 | 관리자 | 2017.03.18 | 4 |
134 | CVE-2017-0086 | 관리자 | 2017.03.18 | 1 |
133 | CVE-2017-0097 | 관리자 | 2017.03.18 | 8 |
132 | CVE-2017-0084 | 관리자 | 2017.03.18 | 1 |
131 | CVE-2017-0096 | 관리자 | 2017.03.18 | 0 |
130 | CVE-2017-0082 | 관리자 | 2017.03.18 | 8 |
129 | CVE-2017-0095 | 관리자 | 2017.03.18 | 1 |
128 | CVE-2017-0080 | 관리자 | 2017.03.18 | 7 |
127 | CVE-2017-0094 | 관리자 | 2017.03.18 | 1 |
126 | CVE-2017-0078 | 관리자 | 2017.03.18 | 7 |
125 | CVE-2017-0071 | 관리자 | 2017.03.18 | 7 |
124 | CVE-2017-0047 | 관리자 | 2017.03.18 | 3 |
123 | CVE-2017-0049 | 관리자 | 2017.03.18 | 8 |