Medium severity6.5NVD Advisory· Published Aug 19, 2020· Updated Jun 17, 2026
CVE-2020-23574
CVE-2020-23574
Description
When uploading a file in Sysax Multi Server 6.90, an authenticated user can modify the filename="" parameter in the uploadfile_name1.htm form to a length of 368 or more bytes. This will create a buffer overflow condition, causing the application to crash.
Affected products
3cpe:2.3:a:sysax:multi_server:6.90:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sysax:multi_server:6.90:*:*:*:*:*:*:*
- (no CPE)range: 6.90
- Sysax/Multi Serverdescription
Patches
Vulnerability mechanics
References
1- www.hosaka.co.uk/2020/06/08/sysax-multi-server-buffer-overflow/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.