mirror of
https://github.com/0xMarcio/cve.git
synced 2025-06-19 17:30:12 +00:00
1.2 KiB
1.2 KiB
CVE-2024-25153
Description
A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portal’s DocumentRoot, specially crafted JSP files could be used to execute code, including web shells.
POC
Reference
No PoCs from references.
Github
- https://github.com/GhostTroops/TOP
- https://github.com/fkie-cad/nvd-json-data-feeds
- https://github.com/nettitude/CVE-2024-25153
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/rainbowhatrkn/CVE-2024-25153
- https://github.com/wjlin0/poc-doc
- https://github.com/wy876/POC
- https://github.com/wy876/wiki