First published: Tue Jul 31 2012(Updated: )
d4d/uploader.php in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allows remote attackers to create or overwrite arbitrary files in %PROGRAMFILES%\Scrutinizer\snmp\mibs\ via a multipart/form-data POST request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWALL Scrutinizer | <9.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2627 is classified as a critical vulnerability due to its ability to allow remote attackers to overwrite arbitrary files.
To fix CVE-2012-2627, upgrade to Plixer Scrutinizer version 9.5.0 or later.
CVE-2012-2627 affects all versions of Plixer Scrutinizer prior to 9.5.0.
CVE-2012-2627 allows for arbitrary file creation or overwriting via a multipart/form-data POST request.
The potential risks include unauthorized access, data corruption, and compromise of sensitive information due to arbitrary file manipulation.