CVE-2011-0678
Unrestricted file upload vulnerability in the EasyEdit module in Lomtec ActiveWeb Professional 3.0 allows remote attackers to execute arbitrary code by uploading an executable file via the UploadDirectory and Accepted Extensions fields in the…
Does this matter?
Lower severity and a low EPSS score (9.21%). Track it; it rarely justifies an emergency change on its own.
Description
Unrestricted file upload vulnerability in the EasyEdit module in Lomtec ActiveWeb Professional 3.0 allows remote attackers to execute arbitrary code by uploading an executable file via the UploadDirectory and Accepted Extensions fields in the getImagefile component of EasyEdit.cfm.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 9.21% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- lomtec/activeweb
- Source
- cve@mitre.org
References
- http://osvdb.org/70669
- http://secunia.com/advisories/43031
- http://www.exploitdevelopment.com/Vulnerabilities/2010-WEB-002.htmlExploit
- http://www.kb.cert.org/vuls/id/528212US Government Resource
- http://www.securityfocus.com/bid/45985Exploit
- http://www.vupen.com/english/advisories/2011/0217
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65013
- http://osvdb.org/70669
- http://secunia.com/advisories/43031
- http://www.exploitdevelopment.com/Vulnerabilities/2010-WEB-002.htmlExploit
- http://www.kb.cert.org/vuls/id/528212US Government Resource
- http://www.securityfocus.com/bid/45985Exploit
- http://www.vupen.com/english/advisories/2011/0217
- https://exchange.xforce.ibmcloud.com/vulnerabilities/65013
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.