9.8
CVSSv3

CVE-2016-10036

Published: 01/05/2018 Updated: 13/06/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory prior to 4.16 allows remote malicious users to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write to arbitrary files and cause a denial of service by uploading an HTML file.

Vulnerable Product Search on Vulmon Subscribe to Product

jfrog artifactory

Exploits

# Exploit Title: Jfrog Artifactory < 416 - Unauthenticated Arbitrary File Upload / Remote Command Execution # Date: 2018-04-25 # Exploit Author: Alessio Sergi # Vendor Homepage: jfrogcom/artifactory/ # Software Link: bintraycom/jfrog/artifactory/download_file?file_path=jfrog-artifactory-oss-4150zip # CVE : CVE-2016-10036 ...
Jfrog Artifactory versions prior to 416 suffer from unauthenticated arbitrary file upload and remote command execution vulnerabilities ...