![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2016-6255 |
Description: | Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request without a registered handler. |
Test IDs: | 1.3.6.1.4.1.25623.1.1.10.2016.0266 1.3.6.1.4.1.25623.1.0.703736 1.3.6.1.4.1.25623.1.1.1.2.2016.597 1.3.6.1.4.1.25623.1.0.106155 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2016-6255 BugTraq ID: 92050 http://www.securityfocus.com/bid/92050 Debian Security Information: DSA-3736 (Google Search) http://www.debian.org/security/2016/dsa-3736 https://www.exploit-db.com/exploits/40589/ https://security.gentoo.org/glsa/201701-52 https://github.com/mjg59/pupnp-code/commit/be0a01bdb83395d9f3a5ea09c1308a4f1a972cbd https://twitter.com/mjg59/status/755062278513319936 https://www.tenable.com/security/research/tra-2017-10 http://www.openwall.com/lists/oss-security/2016/07/18/13 http://www.openwall.com/lists/oss-security/2016/07/20/5 |