Vulnerability Description
Path traversal vulnerability in the administrative panel in KonaKart eCommerce Platform version 8.7 and earlier could allow an attacker to download system files, as well as upload specially crafted JSP files and in turn gain access to the server.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Konakart | Konakart | <= 8.7.0.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/archive/1/541742/100/0/threadedThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/541742/100/0/threadedThird Party AdvisoryVDB Entry
FAQ
What is CVE-2017-17108?
CVE-2017-17108 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Path traversal vulnerability in the administrative panel in KonaKart eCommerce Platform version 8.7 and earlier could allow an attacker to download system files, as well as upload specially crafted JS...
How severe is CVE-2017-17108?
CVE-2017-17108 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-17108?
Check the references section above for vendor advisories and patch information. Affected products include: Konakart Konakart.