A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to upload arbitrary files, leading to arbitrary remote code execution.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HBlaauwproducts Remote Kiln Control
APPBlaauwproducts3.0.0≤ 3.0.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCEPath Traversal
CWE
Powiązane podatności
CVE-2019-18869CRITICAL9.8PL ✓ten sam produkt
RCE przez pozostawiony kod debugowania w Blaauw Remote Kiln Control
CVE-2019-18868CRITICAL9.8PL ✓ten sam produkt
Blaauw Remote Kiln Control — ujawnienie danych uwierzytelniających MySQL w plikach
CVE-2019-18867HIGH7.5ten sam produkt
Browsable directories in Blaauw Remote Kiln Control through v3.00r4 allow an attacker to enumerate sensitive f...
CVE-2019-18872HIGH7.5ten sam produkt
Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessabl...
CVE-2019-18866HIGH7.5ten sam produkt
Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3...