Home
MEDIUM: 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/S:N/AU:N/R:U/V:CMEDIUM: 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:HDefault status
affected
Any version
affected
Default status
unaffected
Any version
affected
Default status
unaffected
Any version
affected
Description
File upload and execute vulnerabilities in ASPECT allow PHP script injection if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
Problem types
CWE-434: Unrestricted Upload of File with Dangerous Type
Product status
Any version
Any version
Any version
References
search.abb.com/...geCode=en&DocumentPartId=pdf&Action=Launch