← Back to CVE List

CVE-2021-37444

Published: 2021-07-25T22:15Z
Last Modified: 2024-11-21T06:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive. This can lead to code execution if a ZIP element's pathname is set to a Windows startup folder, a file for the inbuilt Out-Going Message function, or a file for the the inbuilt Autodial function. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt