CVE-2017-9650
Automated Logic WebCTRL 6.5 - Unrestricted File Upload / Remote Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to upload a malicious file allowing the execution of arbitrary code.
Se ha descubierto un problema de carga de archivos sin restricciones con tipos peligrosos en Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 y anteriores; ALC WebCTRL, SiteScan Web 6.1 y anteriores; ALC WebCTRL, i-Vu 6.0 y anteriores; ALC WebCTRL, i-Vu, SiteScan Web 5.5 y anteriores; y ALC WebCTRL, i-Vu, SiteScan Web 5.2 y anteriores. Un atacante autenticado podría ser capaz de subir un archivo malicioso que permita la ejecución de código arbitrario.
Automated Logic WebCTRL version 6.5 suffers from an unrestricted file upload vulnerability that allows for remote code execution.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-06-14 CVE Reserved
- 2017-08-23 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/100452 | Third Party Advisory | |
https://ics-cert.us-cert.gov/advisories/ICSA-17-234-01 | Mitigation |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/42544 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Automatedlogic Search vendor "Automatedlogic" | I-vu Search vendor "Automatedlogic" for product "I-vu" | <= 5.2 Search vendor "Automatedlogic" for product "I-vu" and version " <= 5.2" | - |
Affected
| ||||||
Automatedlogic Search vendor "Automatedlogic" | I-vu Search vendor "Automatedlogic" for product "I-vu" | <= 5.5 Search vendor "Automatedlogic" for product "I-vu" and version " <= 5.5" | - |
Affected
| ||||||
Automatedlogic Search vendor "Automatedlogic" | I-vu Search vendor "Automatedlogic" for product "I-vu" | <= 6.0 Search vendor "Automatedlogic" for product "I-vu" and version " <= 6.0" | - |
Affected
| ||||||
Automatedlogic Search vendor "Automatedlogic" | I-vu Search vendor "Automatedlogic" for product "I-vu" | <= 6.5 Search vendor "Automatedlogic" for product "I-vu" and version " <= 6.5" | - |
Affected
| ||||||
Automatedlogic Search vendor "Automatedlogic" | Sitescan Web Search vendor "Automatedlogic" for product "Sitescan Web" | <= 5.2 Search vendor "Automatedlogic" for product "Sitescan Web" and version " <= 5.2" | - |
Affected
| ||||||
Automatedlogic Search vendor "Automatedlogic" | Sitescan Web Search vendor "Automatedlogic" for product "Sitescan Web" | <= 5.5 Search vendor "Automatedlogic" for product "Sitescan Web" and version " <= 5.5" | - |
Affected
| ||||||
Automatedlogic Search vendor "Automatedlogic" | Sitescan Web Search vendor "Automatedlogic" for product "Sitescan Web" | <= 6.1 Search vendor "Automatedlogic" for product "Sitescan Web" and version " <= 6.1" | - |
Affected
| ||||||
Automatedlogic Search vendor "Automatedlogic" | Sitescan Web Search vendor "Automatedlogic" for product "Sitescan Web" | <= 6.5 Search vendor "Automatedlogic" for product "Sitescan Web" and version " <= 6.5" | - |
Affected
| ||||||
Carrier Search vendor "Carrier" | Automatedlogic Webctrl Search vendor "Carrier" for product "Automatedlogic Webctrl" | <= 5.2 Search vendor "Carrier" for product "Automatedlogic Webctrl" and version " <= 5.2" | - |
Affected
| ||||||
Carrier Search vendor "Carrier" | Automatedlogic Webctrl Search vendor "Carrier" for product "Automatedlogic Webctrl" | <= 5.5 Search vendor "Carrier" for product "Automatedlogic Webctrl" and version " <= 5.5" | - |
Affected
| ||||||
Carrier Search vendor "Carrier" | Automatedlogic Webctrl Search vendor "Carrier" for product "Automatedlogic Webctrl" | <= 6.0 Search vendor "Carrier" for product "Automatedlogic Webctrl" and version " <= 6.0" | - |
Affected
| ||||||
Carrier Search vendor "Carrier" | Automatedlogic Webctrl Search vendor "Carrier" for product "Automatedlogic Webctrl" | <= 6.1 Search vendor "Carrier" for product "Automatedlogic Webctrl" and version " <= 6.1" | - |
Affected
| ||||||
Carrier Search vendor "Carrier" | Automatedlogic Webctrl Search vendor "Carrier" for product "Automatedlogic Webctrl" | <= 6.5 Search vendor "Carrier" for product "Automatedlogic Webctrl" and version " <= 6.5" | - |
Affected
|