Files
CVEs-PoC/2017/CVE-2017-9644.md
T
2024-06-18 02:51:15 +02:00

18 lines
1015 B
Markdown

### [CVE-2017-9644](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9644)
![](https://img.shields.io/static/v1?label=Product&message=Automated%20Logic%20Corporation%20WebCTRL%2C%20i-VU%2C%20SiteScan&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-428&color=brighgreen)
### Description
An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An unquoted search path vulnerability may allow a non-privileged local attacker to change files in the installation directory and execute arbitrary code with elevated privileges.
### POC
#### Reference
- https://www.exploit-db.com/exploits/42542/
#### Github
No PoCs found on GitHub currently.