packetstormsecurity.com
http://packetstormsecurity.com/files/147378/Jfrog-Artifactory-Code-Execution-Shell-Upload.html CVE-2016-10036
CRITICAL
Jfrog Artifactory < 4.16 - Arbitrary File Upload / Remote Command Execution
Record summary
CVE-2016-10036 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write to arbitrary files and cause a denial of service by uploading an HTML file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBJfrog Artifactory < 4.16 - Arbitrary File Upload / Remote Command ExecutionExploitDB exploitby Alessio SergiNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-10036 44543exploit
https://www.exploit-db.com/exploits/44543 jfrog.comConfirmation
https://www.jfrog.com/confluence/display/RTF/Release+Notes