Webopac from Grand Vice info does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells, which could lead to arbitrary code execution on the server.
Metrics
Affected Vendors & Products
References
History
Mon, 11 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Vice
Vice webopac |
|
CPEs | cpe:2.3:a:vice:webopac:*:*:*:*:*:*:*:* | |
Vendors & Products |
Vice
Vice webopac |
|
Metrics |
ssvc
|
Mon, 11 Nov 2024 07:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Webopac from Grand Vice info does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells, which could lead to arbitrary code execution on the server. | |
Title | Grand Vice info Webopac - Arbitrary File Upload | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2024-11-11T06:54:52.479Z
Updated: 2024-11-11T16:02:12.805Z
Reserved: 2024-11-08T05:54:41.127Z
Link: CVE-2024-11017
Vulnrichment
Updated: 2024-11-11T16:01:53.787Z
NVD
Status : Analyzed
Published: 2024-11-11T07:15:04.910
Modified: 2024-11-18T18:47:19.347
Link: CVE-2024-11017
Redhat
No data.