CVE-2024-48760

An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perlcmd.cgi file that overwrites the original upload.cgi file, enabling remote command execution.
Configurations

No configuration.

History

23 Jan 2025, 17:15

Type Values Removed Values Added
CWE CWE-434
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) Un problema en GestioIP v3.5.7 permite que un atacante remoto ejecute código arbitrario a través de la función de carga de archivos. El atacante puede cargar un archivo perlcmd.cgi malicioso que sobrescriba el archivo upload.cgi original, lo que permite la ejecución remota de comandos.

15 Jan 2025, 00:15

Type Values Removed Values Added
Summary (en) An issue in GestiolP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perlcmd.cgi file that overwrites the original upload.cgi file, enabling remote command execution. (en) An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perlcmd.cgi file that overwrites the original upload.cgi file, enabling remote command execution.

14 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-14 22:15

Updated : 2025-01-23 17:15


NVD link : CVE-2024-48760

Mitre link : CVE-2024-48760

CVE.ORG link : CVE-2024-48760


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type