peter bassill · operator
$ cve CVE-2011-0678 JSON

CVE-2011-0678 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 9.2% (pctl 95)

Patch early

A public exploit exists.

Description

Unrestricted file upload vulnerability in the EasyEdit module in Lomtec ActiveWeb Professional 3.0 allows remote attackers to execute arbitrary code by uploading an executable file via the UploadDirectory and Accepted Extensions fields in the getImagefile component of EasyEdit.cfm.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS9.21% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploityes
Published2011-01-28
Last modified2026-06-16

Affected (1)

VendorProduct
lomtecactiveweb

Public exploits

SourceTitleDate
exploit-dbActiveWeb Professional 3.0 - Arbitrary File Upload2011-01-25

References

→ the Explorer  ·  watch your stack  ·  NVD