First published: Sat Feb 28 2015(Updated: )
KENT-WEB Joyful Note before 5.3 allows remote attackers to delete files or write to files, and consequently execute arbitrary code, via vectors involving an article.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
KENT-WEB Joyful Note | <=5.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0889 is considered to have a moderate severity level due to its potential to allow remote code execution.
To fix CVE-2015-0889, update KENT-WEB Joyful Note to version 5.3 or later.
CVE-2015-0889 can allow attackers to delete or write files on the server, leading to possible arbitrary code execution.
No, CVE-2015-0889 is not exploitable in KENT-WEB Joyful Note versions 5.3 and above.
Users of KENT-WEB Joyful Note versions prior to 5.3 are affected by CVE-2015-0889.