CVE-2016-10036
CRITICALJFrog Artifactory < 4.16 - Unauthenticated Unrestricted File Upload via UI Artifact Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-10036. PoCs published by Alessio Sergi.
AI-analyzed exploit summary This exploit demonstrates unauthenticated arbitrary file upload and directory traversal in Jfrog Artifactory < 4.16, allowing attackers to overwrite files or deploy malicious WAR applications for remote code execution.
Description
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write to arbitrary files and cause a denial of service by uploading an HTML file.
Exploits (1)
This exploit demonstrates unauthenticated arbitrary file upload and directory traversal in Jfrog Artifactory < 4.16, allowing attackers to overwrite files or deploy malicious WAR applications for remote code execution.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H