Webopac from Grand Vice info does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells, which could lead to arbitrary code execution on the server.
References
Link | Resource |
---|---|
https://www.twcert.org.tw/en/cp-139-8212-a7d3a-2.html | Third Party Advisory |
https://www.twcert.org.tw/tw/cp-132-8211-a2da2-1.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
18 Nov 2024, 18:47
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.twcert.org.tw/en/cp-139-8212-a7d3a-2.html - Third Party Advisory | |
References | () https://www.twcert.org.tw/tw/cp-132-8211-a2da2-1.html - Third Party Advisory | |
First Time |
Vice
Vice webopac |
|
CPE | cpe:2.3:a:vice:webopac:*:*:*:*:*:*:*:* |
12 Nov 2024, 13:55
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
11 Nov 2024, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-11 07:15
Updated : 2024-11-18 18:47
NVD link : CVE-2024-11017
Mitre link : CVE-2024-11017
CVE.ORG link : CVE-2024-11017
JSON object : View
Products Affected
vice
- webopac
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type