Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request without a registered handler.
References
Configurations
History
No history.
Information
Published : 2017-03-07 16:59
Updated : 2025-04-20 01:37
NVD link : CVE-2016-6255
Mitre link : CVE-2016-6255
CVE.ORG link : CVE-2016-6255
JSON object : View
Products Affected
libupnp_project
- libupnp
debian
- debian_linux
CWE
CWE-284
Improper Access Control