ZeroHour

CVE-2018-19512

PoC ×2
CVSS 3.0
7.2 high
EPSS
7%p94
Published
()
Modified
Description

In Webgalamb through 7.0, a system/ajax.php "wgmfile restore" directory traversal vulnerability could lead to arbitrary code execution by authenticated administrator users, because PHP files are restored under the document root directory.

Vendors
ens
Products
webgalamb
Weakness
CWE-22
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.