cve/2017/CVE-2017-9602.md
2024-06-18 02:51:15 +02:00

796 B

CVE-2017-9602

Description

KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component. An unauthenticated user can access the file upload and deletion functionality. Through this functionality, a user can upload an ASPX script to Uploads/Documents/ to run any arbitrary code.

POC

Reference

Github