"evaluatorComment":"Per: http://cwe.mitre.org/data/definitions/434.html\r\n\r\n'CWE-434: Unrestricted Upload of File with Dangerous Type'",
"descriptions":[
{
"lang":"en",
"value":"Unrestricted file upload vulnerability in Pulse CMS Basic 1.2.4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in an unspecified directory, a different vulnerability than CVE-2010-0993."
},
{
"lang":"es",
"value":"Vulnerabilidad de subida de fichero sin restricci\u00f3n en Pulse CMS Basic v1.2.4 permite a usuarios autentificados remotamente ejecutar c\u00f3digo de su leeci\u00f3n para subir un archivo con una extensi\u00f3n ejecutable seguido por una extensi\u00f3n de guardado, luego accede a \u00e9l a trav\u00e9s de una petici\u00f3n directa en un directorio no especificado, una vulnerabilidad diferente a CVE-2010-0993."