NVD

Id
17917  
Name
CVE-2016-1524  
Description
Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary Java code by using (1) fileUpload.do or (2) lib-1.0/external/flash/fileUpload.do to upload a JSP file, and then accessing it via a direct request for a /null URI.  
Reject
 
CVSS Version
2  
CVSS Score
8.3  
Severity
High  
CVSS Base Score
8.3  
CVSS Impact Subscore
10  
CVSS Exploit Subscore
6.5  
CVSS Vector
(AV:A/AC:L/Au:N/C:C/I:C/A:C)  
Pub Date
2017-01-19  
Published
2016-02-12  
Modified Date
2016-12-05  
Seq
2016-1524  

Actions