CVE-2017-16610 is a critical vulnerability in Netgain Enterprise Manager, allowing unauthenticated remote attackers to execute arbitrary code. The flaw stems from improper validation of user-supplied paths in the upload_save_do.jsp component, leading to a CVSS score of 9.8. This vulnerability has a high potential impact, enabling attackers to gain full control under the context of the current user. Despite its severity, there is no public exploit code available, nor is there evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.2.766CPE matchmatch criteria | cpe:2.3:a:netgain-systems:enterprise_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R1] NetGain Enterprise Manager Multiple Remote Vulnerabilities
Jan 29, 2018[R1] NetGain Enterprise Manager Multiple Remote Vulnerabilities
Jan 29, 2018NetGain Enterprise Manager Multiple Remote Vulnerabilities
Jan 29, 2018