A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to upload arbitrary files, leading to arbitrary remote code execution.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-05-07T13:06:36
Updated: 2024-08-05T02:02:39.715Z
Reserved: 2019-11-11T00:00:00
Link: CVE-2019-18871
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-05-07T14:15:11.790
Modified: 2024-11-21T04:33:45.557
Link: CVE-2019-18871
Redhat
No data.