CVE Feed

    Dashboard / CVE / CVE-2017-9602

    CVE-2017-9602

    KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component. An unauthenticated user can access the file upload and deletion functionality. Through this functionality, a user can upload an ASPX script to Uploads/Documents/ to run any arbitrary code.

    Published:Jun 16, 2017
    Last Modified:Apr 20, 2025
    EPS:Jun 16, 2017
    EPSS Score:0.07376
    CVSS Score:9.8

    Affected Products

    Vendor
    Kbvault Mysql Project
    Product
    Kbvault Mysql

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High