A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to upload arbitrary files, leading to arbitrary remote code execution.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-05-07T13:06:36

Updated: 2024-08-05T02:02:39.715Z

Reserved: 2019-11-11T00:00:00

Link: CVE-2019-18871

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-05-07T14:15:11.790

Modified: 2020-05-12T13:45:40.300

Link: CVE-2019-18871

cve-icon Redhat

No data.