Security Advisory

CVE-2011-0678

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2011-01-28 20:29:00
Last updated 2024-08-06 21:58:26
Assigner mitre
State PUBLISHED

Description

Unrestricted file upload vulnerability in the EasyEdit module in Lomtec ActiveWeb Professional 3.0 allows remote attackers to execute arbitrary code by uploading an executable file via the UploadDirectory and Accepted Extensions fields in the getImagefile component of EasyEdit.cfm.