CVE-2014-8789 Information

Description

GleamTech FileVista before 6.1 allows remote authenticated users to create arbitrary files and possibly execute arbitrary code via a crafted path in a zip archive which is not properly handled during extraction.

Reference

http://packetstormsecurity.com/files/129304/FileVista-Path-Leakage-Path-Write-Modification.html http://seclists.org/fulldisclosure/2014/Nov/87 http://support.gleamtech.com/kb/a10/version-history-of-filevista.aspx

Share on: