10

CVE-2008-0656

Unrestricted file upload vulnerability in dmclTrace.jsp in EMC Documentum Administrator 5.3.0.313 and Webtop 5.3.0.317 allows remote attackers to overwrite arbitrary files via the filename attribute.

Data is provided by the National Vulnerability Database (NVD)
EmcDocumentum Administrator Version4.2.8
EmcDocumentum Administrator Version5.2.5
EmcDocumentum Administrator Version5.2.5_sp2
EmcDocumentum Administrator Version5.3.0.313
EmcDocumentum Webtop Version5.2.5
EmcDocumentum Webtop Version5.2.5_sp2
EmcDocumentum Webtop Version5.3.0.317
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.08% 0.824
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.