An issue was discovered in Open-AudIT 3.2.2. There is Arbitrary file upload.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://community.opmantek.com/display/OA/Release+Notes+for+Open-AudIT+v3.3.0 | release notes vendor advisory |
https://www.coresecurity.com/advisories/open-audit-multiple-vulnerabilities | third party advisory exploit |