Description
4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in order to perform arbitrary system operations or deny of service attack.
No analysis available yet.
Remediation
Vendor Solution
Update 4MOSAn GCB Doctor version to 20210916(v2.0)
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-31009 | 4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker can upload arbitrary files including webshell files without authentication and execute arbitrary code in order to perform arbitrary system operations or deny of service attack. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-5395-eee40-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-17T00:11:07.348Z
Reserved: 2021-11-23T00:00:00.000Z
Link: CVE-2021-44159
No data.
Status : Modified
Published: 2021-12-20T03:15:06.650
Modified: 2024-11-21T06:30:28.083
Link: CVE-2021-44159
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD