Double Choco Latte (DCL) before 20020706 does not properly verify if a file was uploaded, which allows remote attackers to conduct certain operations on arbitrary files via the (1) Projects: Upload File Attachment or (2) Work Orders: Import features.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Double_choco_latte | Michael_dean | 2002-01-20 (including) | 2002-01-20 (including) |
Double_choco_latte | Michael_dean | 2002-02-15 (including) | 2002-02-15 (including) |