Vulnerabilities > CVE-2017-6100 - Exposure of Resource to Wrong Sphere vulnerability in Tcpdf Project Tcpdf

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
tcpdf-project
CWE-668

Summary

tcpdf before 6.2.0 uploads files from the server generating PDF-files to an external FTP.

Vulnerable Configurations

Part Description Count
Application
Tcpdf_Project
190

Common Weakness Enumeration (CWE)