DreamMaker from Interinfo has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
History

Fri, 29 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Interinfo
Interinfo dreammaker
CPEs cpe:2.3:a:interinfo:dreammaker:*:*:*:*:*:*:*:*
Vendors & Products Interinfo
Interinfo dreammaker
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 29 Nov 2024 02:30:00 +0000

Type Values Removed Values Added
Description DreamMaker from Interinfo has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
Title Interinfo DreamMaker - Unrestricted File Upload through Path Traversal
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2024-11-29T02:12:14.052Z

Updated: 2024-12-03T06:05:57.385Z

Reserved: 2024-11-29T01:52:16.769Z

Link: CVE-2024-11979

cve-icon Vulnrichment

Updated: 2024-11-29T14:47:26.587Z

cve-icon NVD

Status : Received

Published: 2024-11-29T03:15:15.653

Modified: 2024-11-29T03:15:15.653

Link: CVE-2024-11979

cve-icon Redhat

No data.