First published: Thu Feb 07 2008(Updated: )
Unrestricted file upload vulnerability in dmclTrace.jsp in EMC Documentum Administrator 5.3.0.313 and Webtop 5.3.0.317 allows remote attackers to overwrite arbitrary files via the filename attribute.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
EMC Documentum Webtop | =5.3.0.317 | |
EMC Documentum Administrator | =4.2.8 | |
EMC Documentum Administrator | =5.2.5_sp2 | |
EMC Documentum Administrator | =5.2.5 | |
EMC Documentum Administrator | =5.3.0.313 | |
EMC Documentum Webtop | =5.2.5 | |
EMC Documentum Webtop | =5.2.5_sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0656 has a high severity rating due to its potential for arbitrary file overwriting.
To fix CVE-2008-0656, update to the latest patched versions of EMC Documentum Administrator and Webtop.
CVE-2008-0656 affects EMC Documentum Administrator versions 4.2.8, 5.2.5, 5.2.5_sp2, 5.3.0.313 and EMC Documentum Webtop versions 5.2.5, 5.2.5_sp2, 5.3.0.317.
An unrestricted file upload vulnerability allows remote attackers to upload files without proper validation, leading to potential file overwriting.
CVE-2008-0656 can be exploited by remote attackers who can manipulate the filename attribute in file upload forms.