CVE-2024-11979

DreamMaker from Interinfo has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) DreamMaker de Interinfo tiene una vulnerabilidad de Path Traversal y no restringe los tipos de archivos cargados. Esto permite que atacantes remotos no autenticados carguen archivos arbitrarios en cualquier directorio, lo que lleva a la ejecución de código arbitrario al cargar webshells.

29 Nov 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-29 03:15

Updated : 2026-06-17 06:58


NVD link : CVE-2024-11979

Mitre link : CVE-2024-11979

CVE.ORG link : CVE-2024-11979


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type