Executive Summary

Informations
Name CVE-2011-3833 First vendor Publication 2012-01-28
Vendor Cve Last vendor Modification 2017-08-29

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:S/C:P/I:P/A:P)
Cvss Base Score 6 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Medium
Cvss Expoit Score 6.8 Authentication Requires single instance
Calculate full CVSS 2.0 Vectors scores

Detail

Unrestricted file upload vulnerability in ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in an unspecified directory.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3833

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1

ExploitDB Exploits

id Description
2011-11-13 Support Incident Tracker <= 3.65 Remote Command Execution

OpenVAS Exploits

Date Description
2011-11-16 Name : Support Incident Tracker (SiT!) Multiple Input Validation Vulnerabilities
File : nvt/gb_sit_50632.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
77003 Support Incident Tracker ftp_upload_file.php File Upload PHP Code Execution

Metasploit Database

id Description
2011-11-10 Support Incident Tracker Remote Command Execution

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/50632
http://www.securityfocus.com/bid/50896
CERT-VN http://www.kb.cert.org/vuls/id/576355
EXPLOIT-DB http://www.exploit-db.com/exploits/18108
MISC http://packetstormsecurity.org/files/106933/sit_file_upload.rb.txt
http://secunia.com/secunia_research/2011-79/
OSVDB http://www.osvdb.org/77003
SECUNIA http://secunia.com/advisories/45453
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/71237
https://exchange.xforce.ibmcloud.com/vulnerabilities/71651

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
Date Informations
2021-05-04 12:17:42
  • Multiple Updates
2021-04-22 01:21:01
  • Multiple Updates
2020-05-23 13:16:58
  • Multiple Updates
2020-05-23 00:31:15
  • Multiple Updates
2017-08-29 09:23:33
  • Multiple Updates
2016-06-28 18:51:15
  • Multiple Updates
2016-04-26 21:08:39
  • Multiple Updates
2016-03-06 00:24:25
  • Multiple Updates
2016-03-05 21:25:10
  • Multiple Updates
2013-05-10 23:08:38
  • Multiple Updates