Security Advisory

CVE-2017-9602

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-06-16 13:00:00
Last updated 2024-08-05 17:11:02
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component. An unauthenticated user can access the file upload and deletion functionality. Through this functionality, a user can upload an ASPX script to Uploads/Documents/ to run any arbitrary code.