CVE-2018-11345: Malicious File Upload
An unrestricted file upload vulnerability in upload.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data via the POST parameter filename. This can be used to place attacker controlled code on the file system that can then be executed. Further, the filename parameter is vulnerable to path traversal and allows the attacker to place the file anywhere on the system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11345?
CVE-2018-11345 is an unrestricted file upload vulnerability in ASUSTOR AS6202T ADM 3.1.0.RFQ3.
How does CVE-2018-11345 affect ASUSTOR AS6202T?
CVE-2018-11345 allows attackers to upload files and execute arbitrary code on ASUSTOR AS6202T ADM 3.1.0.RFQ3.
What is the severity of CVE-2018-11345?
CVE-2018-11345 has a severity rating of 8.8 (high).
How can I fix CVE-2018-11345?
To fix CVE-2018-11345, update ASUSTOR AS6202T ADM to version 3.1.0.RFQ4 or later.
What are the references for CVE-2018-11345?
The references for CVE-2018-11345 are: http://seclists.org/fulldisclosure/2018/May/2, https://github.com/mefulton/asustorexploit, and https://www.purehacking.com/blog/matthew-fulton/back-to-the-future-asustor-web-exploitation.