CVE-2011-5058

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
10/01/2012
Last modified:
11/04/2025

Description

The CmbWebserver.dll module of the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to create arbitrary directories under the web root by specifying a non-existent directory using \ (backslash) characters in an HTTP GET request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:3ssoftware:codesys:3.4:sp4:patch2:*:*:*:*:*