Description
Flexsense DiskBoss 7.7.14 allows unauthenticated attackers to upload arbitrary files via /Command/Search Files/Directory field, leading to a denial of service by crashing the application.
Problem types
CWE-434: Unrestricted Upload of File with Dangerous Type
Product status
7.7.14
Credits
Paras Bhatia
References
www.exploit-db.com/exploits/48276 (Exploit Database Entry 48276)
www.diskboss.com/ (Official Vendor Homepage)
github.com/...s_7.7.14/raw/master/diskboss_setup_v7.7.14.exe (Software Download Link)
www.vulncheck.com/...-of-service-by-crashing-the-application