ZeroHour

CVE-2017-5869

PoC
CVSS 3.0
8.8 high
EPSS
35%p98
Published
()
Modified
Description

Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a .. (dot dot) in the X-File-Name header.

Vendors
nuxeo
Products
nuxeo
Weakness
CWE-22
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.