An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.php, provides multipart upload functionality that is accessible without authentication and can be used to place a file anywhere on the device's file system. This allows an attacker the ability to upload a PHP shell onto the device and obtain arbitrary code execution as root.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-12-12T18:00:00
Updated: 2024-08-05T20:51:32.327Z
Reserved: 2017-12-12T00:00:00
Link: CVE-2017-17560
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-12-12T18:29:00.230
Modified: 2024-11-21T03:18:10.000
Link: CVE-2017-17560
Redhat
No data.