Intrexx Arbitrary File Upload Vulnerability (CVE-2014-2025)
Release date:
Updated on:
Affected Systems:
Intrexx Professional 6.0
Intrexx Professional 5.2
Description:
Bugtraq id: 71672
CVE (CAN) ID: CVE-2014-2025
Intrexx is an integrated cross-platform development environment that allows you to create and operate Web-based applications, enterprise portals, and internal systems.
The Intrexx Professional 6.0 and 5.2 versions have the Arbitrary File Upload Vulnerability. Attackers can exploit this vulnerability to upload arbitrary files to the affected system.
<* Source: Christian Schneider
*>
Suggestion:
Vendor patch:
Intrexx
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.unitedplanet.com/en/intrexx-6-professional
Refer:
Http://www.christian-schneider.net/advisories/CVE-2014-2025.txt
This article permanently updates the link address: