{"cve":"CVE-2017-17560","epss":{"score":0.73404},"mitre":{"cpes":[],"created":"2017-12-12T18:00:00+00:00","description":"An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.php, provides multipart upload functionality that is accessible without authentication and can be used to place a file anywhere on the device's file system. This allows an attacker the ability to upload a PHP shell onto the device and obtain arbitrary code execution as root.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{}},"mitre_repo_path":"cves/2017/17xxx/CVE-2017-17560.json","references":["https://download.exploitee.rs/file/generic/Exploiteers-DEFCON25.pdf","https://github.com/rapid7/metasploit-framework/pull/9248","https://www.exploit-db.com/exploits/43356/"],"title":null,"updated":"2024-08-05T20:51:32.327000+00:00","vendors":[],"weaknesses":[]},"nvd":{"cpes":["cpe:2.3:h:westerndigital:my_cloud_pr4100:-:*:*:*:*:*:*:*","cpe:2.3:o:westerndigital:my_cloud_pr4100_firmware:2.30.172:*:*:*:*:*:*:*"],"created":"2017-12-12T18:29:00.230000+00:00","description":"An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.php, provides multipart upload functionality that is accessible without authentication and can be used to place a file anywhere on the device's file system. This allows an attacker the ability to upload a PHP shell onto the device and obtain arbitrary code execution as root.","metrics":{"cvssV2_0":{"score":10.0,"vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C"},"cvssV3_0":{"score":9.8,"vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV3_1":{},"cvssV4_0":{}},"nvd_repo_path":"2017/CVE-2017-17560.json","references":["https://download.exploitee.rs/file/generic/Exploiteers-DEFCON25.pdf","https://github.com/rapid7/metasploit-framework/pull/9248","https://www.exploit-db.com/exploits/43356/"],"title":null,"updated":"2026-06-17T01:11:15.707000+00:00","vendors":["westerndigital","westerndigital$PRODUCT$my_cloud_pr4100","westerndigital$PRODUCT$my_cloud_pr4100_firmware"],"weaknesses":["CWE-287"]},"opencve":{"changes":[],"cpes":{"data":["cpe:2.3:h:westerndigital:my_cloud_pr4100:-:*:*:*:*:*:*:*","cpe:2.3:o:westerndigital:my_cloud_pr4100_firmware:2.30.172:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2017-12-12T18:00:00+00:00","provider":"mitre"},"description":{"data":"An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.php, provides multipart upload functionality that is accessible without authentication and can be used to place a file anywhere on the device's file system. This allows an attacker the ability to upload a PHP shell onto the device and obtain arbitrary code execution as root.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{"score":10.0,"vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C"},"provider":"nvd"},"cvssV3_0":{"data":{"score":9.8,"vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"nvd"},"cvssV3_1":{"data":{},"provider":null},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.73404},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{},"provider":null},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://download.exploitee.rs/file/generic/Exploiteers-DEFCON25.pdf","https://github.com/rapid7/metasploit-framework/pull/9248","https://www.exploit-db.com/exploits/43356/"],"providers":["mitre","nvd"]},"title":{"data":null,"provider":null},"updated":{"data":"2025-04-20T01:37:25.860000+00:00","provider":"nvd"},"vendors":{"data":["westerndigital","westerndigital$PRODUCT$my_cloud_pr4100","westerndigital$PRODUCT$my_cloud_pr4100_firmware"],"providers":["nvd"]},"weaknesses":{"data":["CWE-287"],"providers":["nvd"]}}}