cve/2016/CVE-2016-1524.md
2024-05-26 14:27:05 +02:00

965 B

CVE-2016-1524

Description

Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary Java code by using (1) fileUpload.do or (2) lib-1.0/external/flash/fileUpload.do to upload a JSP file, and then accessing it via a direct request for a /null URI.

POC

Reference

Github

No PoCs found on GitHub currently.