Unauthenticated Arbitrary File Upload (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50…
Unauthenticated Arbitrary File Upload (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Unrestricted file upload in patch_contents.php allows uploading malicious files. The `/var/tdf/patch_contents.php` endpoint allows unauthenticated arbitrary file uploads without file type validation, MIME checking, or size restrictions beyond 16MB, enabling attackers to upload malicious files.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
https://cwe.mitre.org/data/definitions/434.html →Open in CWE collection →In applications, particularly web applications, access to functionality is mitigated by an authorization framework. This framework maps Access Control Lists (ACLs) to elements of the application's functionality; particularly URL's for web apps. In the case that the administrator failed to specify an ACL for a particular element, an attacker may be able to access it with impunity. An attacker with the ability to access functionality not properly constrained by ACLs can obtain sensitive information and possibly compromise the entire application. Such an attacker can access resources that must be available only to users at a higher privilege level, can access management sections of the application, or can run queries for data that they otherwise not supposed to.
https://capec.mitre.org/data/definitions/1.html →Open in CAPEC collection →| Product | Vendor | Status |
|---|---|---|
| mozart_dds_next_1000_firmware | * | Tracked |
| mozart_dds_next_100_firmware | * | Tracked |
| mozart_dds_next_2000_firmware | * | Tracked |
| mozart_dds_next_3000_firmware | * | Tracked |
| mozart_dds_next_300_firmware | * | Tracked |
| mozart_dds_next_30_firmware | * | Tracked |
| mozart_dds_next_3500_firmware | * | Tracked |
| mozart_dds_next_500_firmware | * | Tracked |
| mozart_dds_next_50_firmware | * | Tracked |
| mozart_dds_next_6000_firmware | * | Tracked |
| mozart_dds_next_7000_firmware | * | Tracked |
| mozart_next_1000_firmware | * | Tracked |
| mozart_next_100_firmware | * | Tracked |
| mozart_next_2000_firmware | * | Tracked |
| mozart_next_3000_firmware | * | Tracked |
| mozart_next_300_firmware | * | Tracked |
| mozart_next_30_firmware | * | Tracked |
| mozart_next_3500_firmware | * | Tracked |
| mozart_next_500_firmware | * | Tracked |
| mozart_next_50_firmware | * | Tracked |