TROYANOSYVIRUS
Back to CVEs

CVE-2014-2025

CRITICAL
9.8

Description

Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unknown vectors.

This product uses data from the NVD API but is not endorsed or certified by the NVD.