CVE Database
/

CVE-2013-0248

Back to search

CVE-2013-0248

Published: Mar 15, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.

VendorProductVersions

n/a

n/a

affected
n/a

References

58326
vdb-entry
x_refsource_BID
HPSBMU03409
vendor-advisory
x_refsource_HP
90906
vdb-entry
x_refsource_OSVDB
GLSA-202107-39
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now