CVE-2009-1314 is a critical vulnerability affecting Web File Explorer 3.1, allowing unauthenticated remote attackers to create arbitrary files and execute arbitrary code. The vulnerability stems from improper handling of the 'file' parameter in the 'savefile' action within body.asp, enabling the upload of files with executable extensions. With a CVSS score of 10.0, this flaw presents a severe risk of complete compromise (confidentiality, integrity, and availability). While no active exploitation or Metasploit/Nuclei modules are noted, an authentication bypass exploit exists on ExploitDB, and despite its age, the high severity warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.1CPE matchmatch criteria | cpe:2.3:a:webfileexplorer:web_file_explorer:3.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.