CVE-2017-8051

Publication date

2017-04-21 18:00:00

Family

mitre

State

PUBLISHED

Description

Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of the tns_appliance_session_user parameter, a remote attacker can inject arbitrary commands.