CVE-2013-5221

Esri ArcGIS for Server <10.3 - Command Injection

Title source: llm
STIX 2.1

Description

The mobile-upload feature in Esri ArcGIS for Server 10.1 through 10.2 allows remote authenticated users to upload .exe files by leveraging (1) publisher or (2) administrator privileges.

References (2)

Core 2

Scores

EPSS 0.0019
EPSS Percentile 40.1%

Details

Status published
Products (2)
esri/arcgis_server 10.1
esri/arcgis_server 10.2
Published Sep 24, 2013
Tracked Since Feb 18, 2026