cve/2017/CVE-2017-9640.md

18 lines
968 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2017-9640](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9640)
![](https://img.shields.io/static/v1?label=Product&message=Automated%20Logic%20Corporation%20WebCTRL%2C%20i-VU%2C%20SiteScan&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-22&color=brighgreen)
### Description
A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to overwrite files that are used to execute code. This vulnerability does not affect version 6.5 of the software.
### POC
#### Reference
- https://www.exploit-db.com/exploits/42543/
#### Github
No PoCs found on GitHub currently.