The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". The target server can be exploited without authentication.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2019-07-11T18:22:06.876236Z
Updated: 2024-09-17T00:40:32.733Z
Reserved: 2019-04-09T00:00:00
Link: CVE-2019-11062
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-07-11T19:15:12.860
Modified: 2024-11-21T04:20:27.863
Link: CVE-2019-11062
Redhat
No data.