The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 does not restrict the filenames or extensions of uploaded files, which makes it easier for remote attackers to execute arbitrary code or overwrite files by leveraging CVE-2008-7110 and CVE-2008-7109.
References
Configurations
History
21 Nov 2024, 00:58
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/31631 - Vendor Advisory | |
References | () http://www.informit.com/guides/content.aspx?g=security&seqNum=320 - | |
References | () http://www.securityfocus.com/archive/1/495772/100/0/threaded - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/53003 - |
Information
Published : 2009-08-28 15:30
Updated : 2024-11-21 00:58
NVD link : CVE-2008-7111
Mitre link : CVE-2008-7111
CVE.ORG link : CVE-2008-7111
JSON object : View
Products Affected
kyoceramita
- scanner_file_utility
CWE
CWE-264
Permissions, Privileges, and Access Controls