7.5

CVE-2014-2042

Unrestricted file upload vulnerability in the Manage Project functionality in Livetecs Timelive before 6.5.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in a predictable directory in Uploads/.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LivetecsTimeline Version <= 6.2.8
LivetecsTimeline Version2.81
LivetecsTimeline Version2.91
LivetecsTimeline Version2.94
LivetecsTimeline Version3.0.1
LivetecsTimeline Version3.0.3
LivetecsTimeline Version3.0.5
LivetecsTimeline Version3.1.1
LivetecsTimeline Version3.2.1
LivetecsTimeline Version3.5.1
LivetecsTimeline Version3.6.1
LivetecsTimeline Version3.7.1
LivetecsTimeline Version3.8.1
LivetecsTimeline Version4.2.1
LivetecsTimeline Version4.3.1
LivetecsTimeline Version4.9.1
LivetecsTimeline Version5.2.1
LivetecsTimeline Version6.0.1
LivetecsTimeline Version6.2.1
LivetecsTimeline Version6.2.3
LivetecsTimeline Version6.2.4
LivetecsTimeline Version6.2.6
LivetecsTimeline Version6.2.7
LivetecsTimeline Version6.2.71
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.52% 0.795
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.