CVE-2017-14323

SSRF (Server Side Request Forgery) in getRemoteImage.php in Ueditor in Onethink V1.0 and V1.1 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the upfile parameter.
References
Link Resource
http://seclists.org/fulldisclosure/2018/Apr/16 Exploit Mailing List Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:onethink:onethink:1.1:*:*:*:*:*:*:*
cpe:2.3:a:onethink:onethink:1.0:*:*:*:*:*:*:*

Information

Published : 2018-04-10 08:29

Updated : 2018-05-17 10:34


NVD link : CVE-2017-14323

Mitre link : CVE-2017-14323


JSON object : View

CWE
CWE-918

Server-Side Request Forgery (SSRF)

Advertisement

dedicated server usa

Products Affected

onethink

  • onethink