Security Advisory

CVE-2014-2278

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2014-10-17 23:00:00
Last updated 2024-08-06 10:06:00
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Unrestricted file upload vulnerability in op/op.AddFile2.php in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allows remote attackers to execute arbitrary code by uploading a file with an executable extension specified by the partitionIndex parameter and leveraging CVE-2014-2279.2 to access it via the directory specified by the fileId parameter.