8
CVSSv3

CVE-2013-6234

Published: 22/11/2019 Updated: 04/12/2019
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 8 | Impact Score: 5.9 | Exploitability Score: 2.1
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI prior to 4.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, aka "XSS File Upload."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

eng spagobi

Exploits

################################################### 01 ### Advisory Information ### Title: XSS File Upload Date published: 2014-03-01 Date of last update: 2014-03-01 Vendors contacted: Engineering Group Discovered by: Christian Catalano Severity: Medium 02 ### Vulnerability Information ### CVE reference: CVE-2013-6234 CVSS v2 Base Score: 4 ...
SpagoBI version 40 suffers from cross site scripting and arbitrary file upload vulnerabilities The file upload issue could possibly lead to code execution ...