CVE-2014-5468

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
07/02/2020
Last modified:
11/02/2020

Description

A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cfm to specify a malicious PNG file, which could let a remote malicious user obtain sensitive information or execute arbitrary code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:getrailo:railo:*:*:*:*:*:*:*:* 4.2.1.000 (including)