VulnerabilityModified
CVE-2011-1329
WalRack 1.x before 1.1.9 and 2.x before 2.0.7 does not properly restrict file uploads, which allows remote attackers to execute arbitrary PHP code via vectors involving a double extension, as demonstrated by a .php.zzz file.
MEDIUM 6.8EPSS 1.42%
Does this matter?
Lower severity and a low EPSS score (1.42%). Track it; it rarely justifies an emergency change on its own.
Description
WalRack 1.x before 1.1.9 and 2.x before 2.0.7 does not properly restrict file uploads, which allows remote attackers to execute arbitrary PHP code via vectors involving a double extension, as demonstrated by a .php.zzz file.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.42% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- walrus digit/walrack
- Source
- vultures@jpcert.or.jp
References
- http://digit.que.ne.jp/work/index.cgi?WalRackPatch
- http://digit.que.ne.jp/work/index.cgi?WalRack2Patch
- http://jvn.jp/en/jp/JVN46984044/54827/index.html
- http://jvn.jp/en/jp/JVN46984044/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2011-000032
- http://www.securityfocus.com/bid/48001
- https://exchange.xforce.ibmcloud.com/vulnerabilities/67641
- http://digit.que.ne.jp/work/index.cgi?WalRackPatch
- http://digit.que.ne.jp/work/index.cgi?WalRack2Patch
- http://jvn.jp/en/jp/JVN46984044/54827/index.html
- http://jvn.jp/en/jp/JVN46984044/index.html
- http://jvndb.jvn.jp/jvndb/JVNDB-2011-000032
- http://www.securityfocus.com/bid/48001
- https://exchange.xforce.ibmcloud.com/vulnerabilities/67641
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.