CVE-2018-12309: Path Traversal
Published Dec 4, 2018
·Updated
Directory Traversal in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to upload files to arbitrary locations by modifying the "path" URL parameter. NOTE: the "filename" POST parameter is covered by CVE-2018-11345.
Affected Software
2 affected components
ASUSTOR Data Master=3.1.1
ASUSTOR As602t
Event History
Dec 4, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-12309?
CVE-2018-12309 is a directory traversal vulnerability in upload.cgi in ASUSTOR ADM version 3.1.1.
2
How does CVE-2018-12309 work?
CVE-2018-12309 allows attackers to upload files to arbitrary locations by modifying the "path" URL parameter.
3
What is the severity of CVE-2018-12309?
CVE-2018-12309 has a severity rating of 7.5 (high).
4
Which software versions are affected by CVE-2018-12309?
ASUSTOR ADM version 3.1.1 is affected by CVE-2018-12309.
5
How can I fix CVE-2018-12309?
To fix CVE-2018-12309, upgrade to a version of ASUSTOR ADM that is not affected by the vulnerability.