Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows remote attackers to write to files of arbitrary types via unspecified vectors.
References
Configurations
History
21 Nov 2024, 02:42
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.rapid7.com/db/modules/exploit/windows/scada/advantech_webaccess_dashboard_file_upload - | |
References | () http://www.zerodayinitiative.com/advisories/ZDI-16-127 - | |
References | () http://www.zerodayinitiative.com/advisories/ZDI-16-128 - | |
References | () http://www.zerodayinitiative.com/advisories/ZDI-16-129 - | |
References | () https://ics-cert.us-cert.gov/advisories/ICSA-16-014-01 - Third Party Advisory, US Government Resource | |
References | () https://www.exploit-db.com/exploits/39735/ - Exploit |
Information
Published : 2016-01-15 03:59
Updated : 2024-11-21 02:42
NVD link : CVE-2016-0854
Mitre link : CVE-2016-0854
CVE.ORG link : CVE-2016-0854
JSON object : View
Products Affected
advantech
- webaccess
CWE