DreamMaker from Interinfo has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
Metrics
Affected Vendors & Products
References
History
Fri, 29 Nov 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Interinfo
Interinfo dreammaker |
|
CPEs | cpe:2.3:a:interinfo:dreammaker:*:*:*:*:*:*:*:* | |
Vendors & Products |
Interinfo
Interinfo dreammaker |
|
Metrics |
ssvc
|
Fri, 29 Nov 2024 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | DreamMaker from Interinfo has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells. | |
Title | Interinfo DreamMaker - Unrestricted File Upload through Path Traversal | |
Weaknesses | CWE-434 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-12-03T06:05:57.385Z
Reserved: 2024-11-29T01:52:16.769Z
Link: CVE-2024-11979

Updated: 2024-11-29T14:47:26.587Z

Status : Received
Published: 2024-11-29T03:15:15.653
Modified: 2024-11-29T03:15:15.653
Link: CVE-2024-11979

No data.