A issue was discovered in SiteServer CMS 6.9.0. It allows remote attackers to execute arbitrary code because an administrator can add the permitted file extension .aassp, which is converted to .asp because the "as" substring is deleted.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-04-21T15:37:38

Updated: 2024-08-04T22:55:39.680Z

Reserved: 2019-04-21T00:00:00

Link: CVE-2019-11401

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-04-22T11:29:04.313

Modified: 2019-04-24T20:36:31.763

Link: CVE-2019-11401

cve-icon Redhat

No data.