SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2011-0678

Unrestricted file upload vulnerability in the EasyEdit module in Lomtec ActiveWeb Professional 3.0 allows remote attackers to execute arbitrary code by uploading an executable file via the UploadDirectory and Accepted Extensions fields in the…

MEDIUM 6.8EPSS 9.21%

Does this matter?

Lower severity and a low EPSS score (9.21%). Track it; it rarely justifies an emergency change on its own.

Description

Unrestricted file upload vulnerability in the EasyEdit module in Lomtec ActiveWeb Professional 3.0 allows remote attackers to execute arbitrary code by uploading an executable file via the UploadDirectory and Accepted Extensions fields in the getImagefile component of EasyEdit.cfm.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
9.21% probability · 95th percentile
CISA KEV
Not listed
Affected
lomtec/activeweb
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.