CVE Vulnerabilities

CVE-2013-3590

Published: Aug 28, 2013 | Modified: Oct 07, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Unrestricted file upload vulnerability in admin/uploadImage.html in SearchBlox before 7.5 build 1 allows remote attackers to execute arbitrary code by uploading an executable file with the image/jpeg content type, and then accessing this file via unspecified vectors, as demonstrated by access to a JSP file.

Affected Software

Name Vendor Start Version End Version
Searchblox Searchblox * 7.5 (including)
Searchblox Searchblox 6.2-build_1 (including) 6.2-build_1 (including)
Searchblox Searchblox 6.3-build_1 (including) 6.3-build_1 (including)
Searchblox Searchblox 6.4-build_1 (including) 6.4-build_1 (including)
Searchblox Searchblox 6.4-build_2 (including) 6.4-build_2 (including)
Searchblox Searchblox 7.0 (including) 7.0 (including)
Searchblox Searchblox 7.1 (including) 7.1 (including)
Searchblox Searchblox 7.2 (including) 7.2 (including)
Searchblox Searchblox 7.3 (including) 7.3 (including)
Searchblox Searchblox 7.4 (including) 7.4 (including)

References