A path traversal via the iniFile parameter in excel.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to download arbitrary files from the host machine.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-05-07T13:05:31

Updated: 2024-08-05T02:02:39.735Z

Reserved: 2019-11-11T00:00:00

Link: CVE-2019-18870

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-05-07T14:15:11.747

Modified: 2020-05-12T19:19:55.963

Link: CVE-2019-18870

cve-icon Redhat

No data.