Unrestricted file upload vulnerability in chat/sendfile.aspx in ReadyDesk 9.1 allows remote attackers to execute arbitrary code by uploading and requesting a .aspx file.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
http://www.kb.cert.org/vuls/id/294272 | third party advisory us government resource |
http://www.securityfocus.com/bid/92487 | vdb entry |