admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution, because filePath can have directory traversal and fileContent can be valid JSP code.
References
Link | Resource |
---|---|
https://packetstormsecurity.com/files/163709/ObjectPlanet-Opinio-7.13-Shell-Upload.html | Exploit Third Party Advisory VDB Entry |
https://www.objectplanet.com/opinio/changelog.html | Release Notes Vendor Advisory |
Configurations
Information
Published : 2021-07-31 10:15
Updated : 2021-08-09 12:00
NVD link : CVE-2020-26806
Mitre link : CVE-2020-26806
JSON object : View
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
Products Affected
objectplanet
- opinio