CVE-2014-2025
Summary
| CVE | CVE-2014-2025 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-01-31 23:15:00 UTC |
| Updated | 2020-02-13 21:53:00 UTC |
| Description | Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unknown vectors. |
Risk And Classification
Problem Types: CWE-434
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Unitedplanet | Intrexx | 5.2 | All | All | All |
| Application | Unitedplanet | Intrexx | 6.0 | All | All | All |
| Application | Unitedplanet | Intrexx | 5.2 | All | All | All |
| Application | Unitedplanet | Intrexx | 6.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Hinweis - Intrexx Support-Center | CONFIRM | help.unitedplanet.com | Third Party Advisory |
| www.christian-schneider.net/advisories/CVE-2014-2025.txt | MISC | www.christian-schneider.net | Third Party Advisory |
| IBM X-Force Exchange | MISC | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.