O'Reilly WebSite Pro 2.3.7 installs the uploader.exe program with execute permissions for all users, which allows remote attackers to create and execute arbitrary files by directly calling uploader.exe.
| Software | From | Fixed in |
|---|---|---|
| oreilly / website_pro | - | 2.3.7.x |