Lucene search

K
cve[email protected]CVE-2012-6530
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2012-6530

2022-10-0316:15:28
CWE-119
web.nvd.nist.gov
18
cve-2012-6530
sysax multi server
buffer overflow
security vulnerability
remote code execution
nvd

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:S/C:C/I:C/A:C

AI Score

7.8

Confidence

High

EPSS

0.867

Percentile

98.6%

Stack-based buffer overflow in Sysax Multi Server before 5.52, when HTTP is enabled, allows remote authenticated users with the create folder permission to execute arbitrary code via a crafted request.

Affected configurations

NVD
Node
sysaxmulti_serverRange5.50
OR
sysaxmulti_serverMatch4.3
OR
sysaxmulti_serverMatch4.5
VendorProductVersionCPE
sysaxmulti_server4.5cpe:/a:sysax:multi_server:4.5:::
sysaxmulti_server4.3cpe:/a:sysax:multi_server:4.3:::
sysaxmulti_servercpe:/a:sysax:multi_server::::

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:S/C:C/I:C/A:C

AI Score

7.8

Confidence

High

EPSS

0.867

Percentile

98.6%