CVE-2013-4796: Malicious File Upload
Published Dec 27, 2019
·Updated
ReviewBoard 1.6.17 allows code execution by attaching PHP scripts to review request
Affected Software
1 affected component
ReviewBoard ReviewBoard=1.6.17
Event History
Dec 27, 2019
CVE Published
via MITRE·04:24 PM
Data Sourced
via MITRE·04:24 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4796?
CVE-2013-4796 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2013-4796?
To fix CVE-2013-4796, upgrade ReviewBoard to a version that is not affected, such as one later than 1.6.17.
3
What systems are affected by CVE-2013-4796?
CVE-2013-4796 specifically affects ReviewBoard version 1.6.17.
4
Can CVE-2013-4796 lead to data leakage?
Yes, due to the potential for code execution, CVE-2013-4796 can lead to unauthorized access and data leakage.
5
Is CVE-2013-4796 exploitable in a default configuration?
Yes, CVE-2013-4796 can be exploited in a default configuration of ReviewBoard if vulnerable PHP scripts are attached to review requests.