add.asp in DUware DUbanner 3.1 allows remote attackers to execute arbitrary code by uploading files with arbitrary extensions, such as ASP files, probably due to client-side enforcement that can be bypassed. NOTE: some of these details are obtained from third party information, since the raw source is vague.
Threat-Mapped Scoring
Score: 1.8
Priority: P4 - Informational (Low)
S9 – Sabotage of System/App
EPSS
Score: 0.01038 Percentile:
0.76469
CVSS Scoring
CVSS v2 Score: 7.5
Severity:
Mapped CWE(s)
CWE-434
: Unrestricted Upload of File with Dangerous Type
All CAPEC(s)
CAPEC-1: Accessing Functionality Not Properly Constrained by ACLs
CAPEC(s) with Mapped TTPs
CAPEC-1: Accessing Functionality Not Properly Constrained by ACLs
Mapped TTPs: