Dext5 2.7.1402870

CPE Details

Dext5 2.7.1402870
2.7.1402870
2020-05-27
18h25 +00:00
2020-05-27
18h25 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:dext5:dext5:2.7.1402870:*:*:*:*:*:*:*

Informations

Vendor

dext5

Product

dext5

Version

2.7.1402870

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2020-7832 2021-09-07 12h47 +00:00 A vulnerability (improper input validation) in the DEXT5 Upload solution allows an unauthenticated attacker to download and execute an arbitrary file via AddUploadFile, SetSelectItem, DoOpenFile function.(CVE-2020-7832)
9.8
Critique
CVE-2020-13894 2020-06-06 22h33 +00:00 handler/upload_handler.jsp in DEXT5 Editor through 3.5.1402961 allows an attacker to download arbitrary files via the savefilepath field.
7.5
Haute
CVE-2020-13442 2020-05-25 12h25 +00:00 A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp handler because the uploaded file is stored under dext5uploadeddata/.
9.8
Critique