[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    [oss-security] CVE Request - Intelliants Subrion CMS Arbitrary Files Delete
From:       æ› <hongkun.zeng () dbappsecurity ! com ! cn>
Date:       2016-08-27 14:14:13
Message-ID: 654bd3de.fa5.156cc59cf29.Coremail.hongkun.zeng () dbappsecurity ! com ! cn
[Download RAW message or body]

[Attachment #2 (text/plain)]

Intelliants Subrion CMS Arbitrary Files Delete
This vulnerability allows remote authenticated users to delete arbitrary files on the server.
Fix commit: https://github.com/intelliants/subrion/commit/bf2596f2ab27e37456910886e69b48484a76dd64


The auto-upgrader patch has been released.
Could you allocate a CVE ID for this?


Thank you

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic