admin/file.do in ObjectPlanet Opinio before 7.15 allows Unrestricted File Upload of executable JSP files, resulting in remote code execution, because filePath can have directory traversal and fileContent can be valid JSP code.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-07-31T16:13:31

Updated: 2021-07-31T16:47:48

Reserved: 2020-10-07T00:00:00


Link: CVE-2020-26806

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-07-31T17:15:07.913

Modified: 2022-06-28T14:11:45.273


Link: CVE-2020-26806

JSON object: View

cve-icon Redhat Information

No data.

CWE