Vulnerabilities
Vulnerable Software
Idearespa:  Security Vulnerabilities
A directory traversal vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to download arbitrary .dwg files from a remote server by specifying an absolute or relative path when invoking the affected DownloadDwg endpoint. An attack uses the path field to CaddemServiceJS/CaddemService.svc/rest/DownloadDwg.
CVSS Score
6.5
EPSS Score
0.003
Published
2022-04-03
An unrestricted file upload vulnerability in IdeaRE RefTree before 2021.09.17 allows remote authenticated users to execute arbitrary code by using UploadDwg to upload a crafted aspx file to the web root, and then visiting the URL for this aspx resource.
CVSS Score
8.8
EPSS Score
0.043
Published
2022-04-03


Contact Us

Shodan ® - All rights reserved