The HTTP API in Prismview System 9 11.10.17.00 and Prismview Player 11 13.09.1100 allows remote code execution by uploading RebootSystem.lnk and requesting /REBOOTSYSTEM or /RESTARTVNC. (Authentication is required but an XML file containing credentials can be downloaded.)
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.exploit-db.com/papers/47535 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-02-10T14:39:06
Updated: 2024-08-05T02:39:10.097Z
Reserved: 2020-02-10T00:00:00
Link: CVE-2019-20451
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-02-10T15:15:21.433
Modified: 2024-11-21T04:38:30.597
Link: CVE-2019-20451
Redhat
No data.