A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to upload arbitrary files, leading to arbitrary remote code execution.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HBlaauwproducts Remote Kiln Control
APPBlaauwproducts3.0.0≤ 3.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEPath Traversal
CWE
Related vulnerabilities
CVE-2019-18869CRITICAL9.8PL ✓same product
RCE przez pozostawiony kod debugowania w Blaauw Remote Kiln Control
CVE-2019-18868CRITICAL9.8PL ✓same product
Blaauw Remote Kiln Control — ujawnienie danych uwierzytelniających MySQL w plikach
CVE-2019-18867HIGH7.5same product
Browsable directories in Blaauw Remote Kiln Control through v3.00r4 allow an attacker to enumerate sensitive f...
CVE-2019-18872HIGH7.5same product
Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessabl...
CVE-2019-18866HIGH7.5same product
Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3...