7.8
CVE-2017-9650
- EPSS 1.27%
- Veröffentlicht 25.08.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to upload a malicious file allowing the execution of arbitrary code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Automatedlogic ≫ I-vu Version <= 5.2
Automatedlogic ≫ I-vu Version <= 5.5
Automatedlogic ≫ I-vu Version <= 6.0
Automatedlogic ≫ I-vu Version <= 6.5
Automatedlogic ≫ Sitescan Web Version <= 5.2
Automatedlogic ≫ Sitescan Web Version <= 5.5
Automatedlogic ≫ Sitescan Web Version <= 6.1
Automatedlogic ≫ Sitescan Web Version <= 6.5
Carrier ≫ Automatedlogic Webctrl Version <= 5.2
Carrier ≫ Automatedlogic Webctrl Version <= 5.5
Carrier ≫ Automatedlogic Webctrl Version <= 6.0
Carrier ≫ Automatedlogic Webctrl Version <= 6.1
Carrier ≫ Automatedlogic Webctrl Version <= 6.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.27% | 0.789 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.