### [CVE-2017-9650](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9650) ![](https://img.shields.io/static/v1?label=Product&message=Automated%20Logic%20Corporation%20WebCTRL%2C%20i-VU%2C%20SiteScan&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-434&color=brighgreen) ### Description An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to upload a malicious file allowing the execution of arbitrary code. ### POC #### Reference - https://www.exploit-db.com/exploits/42544/ #### Github No PoCs found on GitHub currently.