DreamMaker from Interinfo has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
Metrics
Affected Vendors & Products
References
History
Fri, 29 Nov 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Interinfo
Interinfo dreammaker |
|
CPEs | cpe:2.3:a:interinfo:dreammaker:*:*:*:*:*:*:*:* | |
Vendors & Products |
Interinfo
Interinfo dreammaker |
|
Metrics |
ssvc
|
Fri, 29 Nov 2024 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | DreamMaker from Interinfo has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells. | |
Title | Interinfo DreamMaker - Unrestricted File Upload through Path Traversal | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2024-11-29T02:12:14.052Z
Updated: 2024-12-03T06:05:57.385Z
Reserved: 2024-11-29T01:52:16.769Z
Link: CVE-2024-11979
Vulnrichment
Updated: 2024-11-29T14:47:26.587Z
NVD
Status : Received
Published: 2024-11-29T03:15:15.653
Modified: 2024-11-29T03:15:15.653
Link: CVE-2024-11979
Redhat
No data.