CVE-2017-1000194: Malicious File Upload
Published Nov 17, 2017
·Updated
October CMS build 412 is vulnerable to Apache configuration modification via file upload functionality resulting in site compromise and possibly other applications on the server.
Affected Software
2 affected componentsFixes available
composer/october/october<=1.0.412
1.0.413
October CMS Debugbar<=1.0.412
Remediation
Event History
Nov 17, 2017
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
May 13, 2022
Advisory Published
01:24 AM
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2017-1000194.
2
What is the severity of CVE-2017-1000194?
The severity of CVE-2017-1000194 is critical.
3
How does the vulnerability CVE-2017-1000194 affect October CMS?
The vulnerability CVE-2017-1000194 affects October CMS build 412.
4
What is the risk of CVE-2017-1000194?
The risk of CVE-2017-1000194 is site compromise and possible compromise of other applications on the server.
5
How can I fix the vulnerability CVE-2017-1000194?
To fix the vulnerability CVE-2017-1000194, update October CMS to version 1.0.413.