Unrestricted file upload vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to execute arbitrary JSP code via vectors involving an upload of an image file.
References
Link Resource
https://ics-cert.us-cert.gov/advisories/ICSA-15-300-02 Patch Third Party Advisory US Government Resource
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: icscert

Published: 2015-10-28T10:00:00

Updated: 2015-10-28T04:57:01

Reserved: 2015-10-22T00:00:00


Link: CVE-2015-7904

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2015-10-28T10:59:24.767

Modified: 2015-10-28T21:05:38.960


Link: CVE-2015-7904

JSON object: View

cve-icon Redhat Information

No data.