go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Grand Vice info Co. webopac7 - Arbitrary File Upload

TVN ID TVN-202111004
CVSS 8.8 (High)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products Grand Vice info Co. webopac7 v7.1.20160701 & v1.8.20160701
Description Grand Vice info Co. webopac7 file upload function fails to filter special characters. While logging in with general user’s permission, remote attackers can upload malicious script and execute arbitrary code to control the system or interrupt services.
Solution Contact tech support from Grand Vice info Co.
Credit ZHENG FU FANG、Yu ChengLi
Public Date 2021-11-15
Top