Intrexx CVE-2014-2025 Unspecified Arbitrary File Upload Vulnerability
BID:71672
Info
Intrexx CVE-2014-2025 Unspecified Arbitrary File Upload Vulnerability
| Bugtraq ID: | 71672 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2025 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2014 12:00AM |
| Updated: | Dec 14 2014 12:00AM |
| Credit: | Christian Schneider |
| Vulnerable: |
United Planet Intrexx 6.0 United Planet Intrexx 5.2 |
| Not Vulnerable: |
United Planet Intrexx 6.0 Online Update 10 United Planet Intrexx 5.2 Online Update 09 |
Discussion
Intrexx CVE-2014-2025 Unspecified Arbitrary File Upload Vulnerability
Intrexx is prone to an unspecified arbitrary file-upload vulnerability because it fails to properly validate the file extensions when uploading them.
An attacker may leverage this issue to upload arbitrary files to the affected system; this can result in arbitrary code execution within the context of the affected application.
Intrexx is prone to an unspecified arbitrary file-upload vulnerability because it fails to properly validate the file extensions when uploading them.
An attacker may leverage this issue to upload arbitrary files to the affected system; this can result in arbitrary code execution within the context of the affected application.
References
Intrexx CVE-2014-2025 Unspecified Arbitrary File Upload Vulnerability
References:
References:
- CVE-2014-2025 Remote Code Execution (RCE) in "Intrexx Professional" (Christian Schneider)
- Intrexx Product Page (United Planet)