6.5
CVSSv2

CVE-2015-7904

Published: 28/10/2015 Updated: 28/10/2015
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x prior to 2.6.0 build 430 allows remote authenticated users to execute arbitrary JSP code via vectors involving an upload of an image file.

Vulnerable Product Search on Vulmon Subscribe to Product

infinite automation systems mango automation 2.5.5

infinite automation systems mango automation 2.5.0

infinite automation systems mango automation 2.6.0

Exploits

Mango Automation 260 CSRF File Upload And Arbitrary JSP Code Execution Vendor: Infinite Automation Systems Inc Product web page: wwwinfiniteautomationcom/ Affected version: 252 and 260 beta (build 327) Summary: Mango Automation is a flexible SCADA, HMI And Automation software application that allows you to view, log, graph, anima ...