TROYANOSYVIRUS
Back to CVEs

CVE-2017-8051

N/A

Description

Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of the tns_appliance_session_user parameter, a remote attacker can inject arbitrary commands.

CVE Details

CVSS v3.1 ScoreN/A
Published4/21/2017
Last Modified4/20/2025
Sourcenvd
Honeypot Sightings0

Affected Products

tenable:appliance

Weaknesses (CWE)

CWE-78

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.