W Sangfor Operation and Maintenance Management System do wersji 3.0.8 odkryto lukę bezpieczeństwa. Podatny element znajduje się w nieznanej funkcji pliku /fort/trust/version/common/common.jsp, gdzie manipulacja parametrem File prowadzi do unrestricted upload. Atak można wykonać zdalnie, exploit został ujawniony publicznie, a producent nie odpowiedział na zawiadomienie.
▸ Pokaż oryginał (EN)
A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function of the file /fort/trust/version/common/common.jsp. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSangfor Operation And Maintenance Security Management System
APPSangfor≤ 3.0.8
Powiązane podatności
A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected b...
A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is...
W Sangfor Operation and Maintenance Security Management System do wersji 3.0.12 odkryto podatność. Zagrożona j...
W systemie Sangfor Operation and Maintenance Security Management System do wersji 3.0.12 odkryto lukę bezpiecz...
W Sangfor Operation and Maintenance Management System do wersji 3.0.8 zidentyfikowano podatność. Podatny eleme...