Sploitus

CVE-2017-5869

6 known exploits for CVE-2017-5869

Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a .. (dot dot) in the X-File-Name header.

Affected products
Nuxeo Platform
Nuxeo
= 6.0, 7.1, 7.2, 7.3
Fix
Available
CVSS 3.0
8.8 HIGH
EPSS
34.6% (98th percentile)
Weakness
CWE-22
NVD status
Modified
Published
2017-03-24
CVE-2017-5869 at NVD
Authoritative description, scoring and affected products

6 known exploits for CVE-2017-5869

Proof-of-concept code and exploit modules indexed by Sploitus