A path traversal via the iniFile parameter in excel.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to download arbitrary files from the host machine.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-05-07T13:05:31

Updated: 2024-08-05T02:02:39.735Z

Reserved: 2019-11-11T00:00:00

Link: CVE-2019-18870

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-05-07T14:15:11.747

Modified: 2024-11-21T04:33:45.417

Link: CVE-2019-18870

cve-icon Redhat

No data.