CVE-2020-5632
Summary
| CVE | CVE-2020-5632 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-06 06:15:00 UTC |
| Updated | 2020-10-22 19:04:00 UTC |
| Description | InfoCage SiteShell series (Host type SiteShell for IIS V1.4, V1.5, and V1.6, Host type SiteShell for IIS prior to revision V2.0.0.6, V2.1.0.7, V2.1.1.6, V3.0.0.11, V4.0.0.6, V4.1.0.5, and V4.2.0.1, Host type SiteShell for Apache Windows V1.4, V1.5, and V1.6, and Host type SiteShell for Apache Windows prior to revision V2.0.0.6, V2.1.0.7, V2.1.1.6, V3.0.0.11, V4.0.0.6, V4.1.0.5, and V4.2.0.1) allow authenticated attackers to bypass access restriction and to execute arbitrary code with an elevated privilege via a specially crafted executable files. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nec | Infocage Siteshell | All | All | All | All |
| Application | Nec | Infocage Siteshell | All | All | All | All |
| Application | Nec | Infocage Siteshell | 1.4 | All | All | All |
| Application | Nec | Infocage Siteshell | 1.4 | All | All | All |
| Application | Nec | Infocage Siteshell | 1.5 | All | All | All |
| Application | Nec | Infocage Siteshell | 1.5 | All | All | All |
| Application | Nec | Infocage Siteshell | 1.6 | All | All | All |
| Application | Nec | Infocage Siteshell | 1.6 | All | All | All |
| Application | Nec | Infocage Siteshell | All | All | All | All |
| Application | Nec | Infocage Siteshell | All | All | All | All |
| Application | Nec | Infocage Siteshell | 1.4 | All | All | All |
| Application | Nec | Infocage Siteshell | 1.4 | All | All | All |
| Application | Nec | Infocage Siteshell | 1.5 | All | All | All |
| Application | Nec | Infocage Siteshell | 1.5 | All | All | All |
| Application | Nec | Infocage Siteshell | 1.6 | All | All | All |
| Application | Nec | Infocage Siteshell | 1.6 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| インストールしたファイルに Everyone による変更権限が付与される際のInfoCage SiteShellの対応について: Webアプリケーションファイアウォール(WAF) InfoCage SiteShell | NEC | MISC | jpn.nec.com | Vendor Advisory |
| JVN#07426151: InfoCage SiteShell installs their files with improper access permissions | MISC | jvn.jp | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.