First published: Fri Jan 31 2020(Updated: )
Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unknown vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Intrexx Portal Server | =5.2 | |
Intrexx Portal Server | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2025 is considered a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2014-2025, upgrade to United Planet Intrexx Professional version 5.2 Online Update 0905 or 6.0 Online Update 10 or later.
CVE-2014-2025 affects United Planet Intrexx Professional versions 5.2 prior to Online Update 0905 and 6.0 prior to Online Update 10.
CVE-2014-2025 is an unrestricted file upload vulnerability that allows remote attackers to execute arbitrary code.
Yes, CVE-2014-2025 can be exploited remotely through uploaded files with executable extensions.