The default configuration of BSCW (Basic Support for Cooperative Work) 3.x and possibly version 4 enables user self registration, which could allow remote attackers to upload files and possibly join a user community that was intended to be closed.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bscw | Fraunhofer_fit | 3.4 (including) | 3.4 (including) |
Bscw | Fraunhofer_fit | 4.0 (including) | 4.0 (including) |
Bscw | Fraunhofer_fit | 4.0.6 (including) | 4.0.6 (including) |