CVE-2019-17327

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
08/11/2019
Last modified:
13/11/2019

Description

JEUS 7 Fix#0~5 and JEUS 8Fix#0~1 versions contains a directory traversal vulnerability caused by improper input parameter check when uploading installation file in administration web page. That leads remote attacker to execute arbitrary code via uploaded file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tmaxsoft:jeus:7:fix_0:*:*:*:*:*:*
cpe:2.3:a:tmaxsoft:jeus:7:fix_5:*:*:*:*:*:*
cpe:2.3:a:tmaxsoft:jeus:8:fix_0:*:*:*:*:*:*
cpe:2.3:a:tmaxsoft:jeus:8:fix_1:*:*:*:*:*:*