The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 does not restrict the filenames or extensions of uploaded files, which makes it easier for remote attackers to execute arbitrary code or overwrite files by leveraging CVE-2008-7110 and CVE-2008-7109.
References
Configurations
Information
Published : 2009-08-28 08:30
Updated : 2018-10-11 13:58
NVD link : CVE-2008-7111
Mitre link : CVE-2008-7111
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
kyoceramita
- scanner_file_utility