메뉴 건너뛰기

GREATUSER

cve

CVE-2017-16610

관리자 2018.01.25 04:00 조회 수 : 173

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within upload_save_do.jsp. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code under the context of the current user. Was ZDI-CAN-4751.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-16610
번호 제목 글쓴이 날짜 조회 수
122 CVE-2017-0033 관리자 2017.03.18 132
121 CVE-2017-0072 관리자 2017.03.18 171
120 CVE-2017-0034 관리자 2017.03.18 225
119 CVE-2017-0070 관리자 2017.03.18 202
118 CVE-2017-0069 관리자 2017.03.18 113
117 CVE-2017-0073 관리자 2017.03.18 163
116 CVE-2017-0067 관리자 2017.03.18 162
115 CVE-2017-0066 관리자 2017.03.18 117
114 CVE-2017-0068 관리자 2017.03.18 173
113 CVE-2017-0063 관리자 2017.03.18 118
112 CVE-2017-0062 관리자 2017.03.18 119
111 CVE-2017-0065 관리자 2017.03.18 89
110 CVE-2017-0060 관리자 2017.03.18 188
109 CVE-2017-0059 관리자 2017.03.18 198
108 CVE-2017-0061 관리자 2017.03.18 89
위로