Automated Logic WebCTRL 6.1 Path...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Description The vulnerability is triggered by an authenticated user that can use the manualcommand console in the management panel of the affected application. The ManualCommand() function in ManualCommand.js allows users to perform additional diagnostics and settings overview by using pre-defined set of commands. This can be exploited by using the echo command to write and/or overwrite arbitrary files on the system including directory traversal throughout the system. ### Vendor Automated Logic Corporation - http://www.automatedlogic.com ### Affected Version * ALC WebCTRL, SiteScan Web 6.1 and prior * ALC WebCTRL, i-Vu 6.0 and prior * ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior * ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior * Note: Current supported versions are 6.5, 6.1 and 6.0 ### Tested On * Microsoft Windows 7 Professional (6.1.7601 Service Pack 1 Build 7601) * Apache-Coyote/1.1 * Apache Tomcat/7.0.42 * CJServer/1.1 * Java/1.7.0_25-b17 * Java HotSpot Server VM 23.25-b01...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息