HIGH🇵🇱 Wersja polska

CVE-2019-18871

CVSS 8.8v3.1pub. 2020-05-07upd. 2024-11-21

A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to upload arbitrary files, leading to arbitrary remote code execution.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Blaauwproducts Remote Kiln Control

    APP
    Blaauwproducts
    3.0.0≤ 3.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEPath Traversal
CWE
References

Related vulnerabilities

CVE-2019-18869CRITICAL9.8PL ✓same product

RCE przez pozostawiony kod debugowania w Blaauw Remote Kiln Control

CVE-2019-18868CRITICAL9.8PL ✓same product

Blaauw Remote Kiln Control — ujawnienie danych uwierzytelniających MySQL w plikach

CVE-2019-18867HIGH7.5same product

Browsable directories in Blaauw Remote Kiln Control through v3.00r4 allow an attacker to enumerate sensitive f...

CVE-2019-18872HIGH7.5same product

Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessabl...

CVE-2019-18866HIGH7.5same product

Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3...