9.4
CVSSv2

CVE-2012-2627

Published: 31/07/2012 Updated: 12/03/2018
CVSS v2 Base Score: 9.4 | Impact Score: 9.2 | Exploitability Score: 10
VMScore: 945
Vector: AV:N/AC:L/Au:N/C:N/I:C/A:C

Vulnerability Summary

d4d/uploader.php in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) prior to 9.5.0 allows remote malicious users to create or overwrite arbitrary files in %PROGRAMFILES%\Scrutinizer\snmp\mibs\ via a multipart/form-data POST request.

Vulnerable Product Search on Vulmon Subscribe to Product

sonicwall scrutinizer

Exploits

source: wwwsecurityfocuscom/bid/54726/info Scrutinizer is prone to a vulnerability that lets attackers upload arbitrary files The issue occurs because the application fails to adequately sanitize user-supplied input An attacker may leverage this issue to upload arbitrary files to the affected computer; this can result in arbitrary code ...
Scrutinizer NetFlow and sFlow Analyzer versions 901 and below suffer from bypass, cross site scripting, and remote file upload vulnerabilities It also has undocumented MySQL admin users ...