CVE-2017-5869 EXPLOIT
8.8
HIGH · CVSS 3.0 · EPSS 34.6% (pctl 98)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a .. (dot dot) in the X-File-Name header.
Scoring
| CVSS | 8.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 34.59% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-03-24 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| nuxeo | nuxeo |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Nuxeo 6.0/7.1/7.2/7.3 - Remote Code Execution (Metasploit) | 2017-03-27 |
References
- http://www.openwall.com/lists/oss-security/2017/03/23/6
- http://www.securityfocus.com/bid/97083
- https://sysdream.com/news/lab/2017-03-23-cve-2017-5869-nuxeo-platform-remote-code-execution/
- https://www.exploit-db.com/exploits/41748/
- http://www.openwall.com/lists/oss-security/2017/03/23/6
- http://www.securityfocus.com/bid/97083
- https://sysdream.com/news/lab/2017-03-23-cve-2017-5869-nuxeo-platform-remote-code-execution/
- https://www.exploit-db.com/exploits/41748/
→ the Explorer · watch your stack · NVD