CVE-2017-5869
Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a .. (dot dot) in the X-File-Name header.
- Affected products
- Nuxeo Platform
- Nuxeo
- = 6.0, 7.1, 7.2, 7.3
- Fix
- Available
- CVSS 3.0
- 8.8 HIGH
- EPSS
- 34.6% (98th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2017-03-24
CVE-2017-5869 at NVD
6 known exploits for CVE-2017-5869
Proof-of-concept code and exploit modules indexed by Sploitus
Intel AMT Digest Authentication Bypass Scanner Exploit
Nuxeo 6.0 / 7.1 / 7.2 / 7.3 - Remote Code Execution Exploit
Nuxeo 6.07.17.27.3 - Remote Code Execution (Metasploit)
Nuxeo 6.0/7.1/7.2/7.3 - Remote Code Execution (Metasploit)
Nuxeo Platform 6.x / 7.x Shell Upload Exploit
Nuxeo Platform 6.x / 7.x Shell Upload