Files
CVEs-PoC/2017/CVE-2017-9602.md
T
2024-06-09 00:33:16 +00:00

842 B

CVE-2017-9602

Description

KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component. An unauthenticated user can access the file upload and deletion functionality. Through this functionality, a user can upload an ASPX script to Uploads/Documents/ to run any arbitrary code.

POC

Reference

Github