First published: Sun Feb 24 2013(Updated: )
BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under AntServer\DocData\Public via unspecified vectors.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
BigAntSoft BigAnt IM Message Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-6274 has a high severity rating due to the potential for unauthorized file uploads, which could compromise the system's integrity.
To fix CVE-2012-6274, ensure that proper authentication measures are implemented for file uploading on the BigAnt IM Message Server.
CVE-2012-6274 can allow attackers to create arbitrary files on the server, leading to data leakage or system compromise.
All users of BigAntSoft BigAnt IM Message Server that do not enforce file upload authentication are vulnerable to CVE-2012-6274.
Mitigation strategies for CVE-2012-6274 include restricting file upload capabilities to authenticated users and regularly updating the software.