5

CVE-2011-1409

Frams's Fast File EXchange (F*EX, aka fex) 20100208, and possibly other versions before 20110610, allows remote attackers to bypass authentication and upload arbitrary files via a request that lacks an authentication ID.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ulli HorlacherFex Version20100208
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.29% 0.809
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://fex.rus.uni-stuttgart.de/fex.html
Patch
http://secunia.com/advisories/44940
Vendor Advisory
http://www.debian.org/security/2011/dsa-2259
http://www.securityfocus.com/bid/48239
https://exchange.xforce.ibmcloud.com/vulnerabilities/68005