cve/2023/CVE-2023-42000.md
2024-06-18 02:51:15 +02:00

880 B

CVE-2023-42000

Description

Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthenticated remote attacker can exploit it to upload arbitrary files to any location on the file system where the UDP agent is installed.

POC

Reference

Github

No PoCs found on GitHub currently.