Back to search
CVE-2017-5965
Published: May 23, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZIP archive in which a .asp file has a ..\ in its pathname, visiting sitecore/shell/applications/install/dialogs/Upload%20Package/UploadPackage2.aspx to upload this archive and extract its contents, and visiting a URI under sitecore/ to execute the .asp file.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://research.aurainfosec.io/disclosures/2017-05-18-sitecore/
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now