VulnerabilityModified
CVE-2007-5401
Unrestricted file upload vulnerability in uploadrequest.asp in Layton HelpBox 3.7.1 allows remote authenticated users to upload and execute arbitrary ASP files, related to not properly checking file extensions.
MEDIUM 6.5EPSS 1.11%
Does this matter?
Lower severity and a low EPSS score (1.11%). Track it; it rarely justifies an emergency change on its own.
Description
Unrestricted file upload vulnerability in uploadrequest.asp in Layton HelpBox 3.7.1 allows remote authenticated users to upload and execute arbitrary ASP files, related to not properly checking file extensions.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.11% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- layton technology/helpbox
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://secunia.com/advisories/27699Vendor Advisory
- http://secunia.com/secunia_research/2007-94/advisory/Vendor Advisory
- http://www.securityfocus.com/bid/27187
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39536
- http://secunia.com/advisories/27699Vendor Advisory
- http://secunia.com/secunia_research/2007-94/advisory/Vendor Advisory
- http://www.securityfocus.com/bid/27187
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39536
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.