The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this vulnerability to upload any file to any location. They may even upload malicious web page files to the website directory, allowing arbitrary system commands to be executed upon browsing the webpage.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2024-06-14T03:53:51.560Z

Updated: 2024-08-02T01:46:04.773Z

Reserved: 2024-03-29T07:18:19.359Z

Link: CVE-2024-31161

cve-icon Vulnrichment

Updated: 2024-07-16T17:06:46.489Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-14T04:15:42.323

Modified: 2024-08-16T20:25:11.357

Link: CVE-2024-31161

cve-icon Redhat

No data.