CVE-2020-7875
Last modified
CVE-2020-7875 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged for code execution.. EPSS estimates a 0.61% chance of exploitation in the next 30 days.
Description
DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged for code execution.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dext5 | Dext5upload | <= 5.0.0.117 |
References
- https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36312Third Party Advisory
- https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36312Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-7875?
How severe is CVE-2020-7875?
How do I fix CVE-2020-7875?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-7869An improper input validation vulnerability of ZOOK software …8.8
- CVE-2020-7870A memory corruption vulnerability exists when ezPDF improper…7.2
- CVE-2020-7871A vulnerability of Helpcom could allow an unauthenticated at…9.8
- CVE-2020-7872DaviewIndy v8.98.7.0 and earlier versions have a Integer ove…7.8
- CVE-2020-7873Download of code without integrity check vulnerability in Ac…9.8
- CVE-2020-7874Download of code without integrity check vulnerability in NE…8.8
- CVE-2020-7877A buffer overflow issue was discovered in ZOOK solution(remo…8.8
- CVE-2020-7878An arbitrary file download and execution vulnerability was f…9.8
- CVE-2020-7879This issue was discovered when the ipTIME C200 IP Camera was…9.8
- CVE-2020-7880The vulnerabilty was discovered in ActiveX module related to…8.8
- CVE-2020-7881The vulnerability function is enabled when the streamer serv…8.8
- CVE-2020-7882Using the parameter of getPFXFolderList function, attackers …9.1
Are you affected by CVE-2020-7875?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
