ZeroHour

CVE-2019-18870

PoC
CVSS 3.1
6.5 medium
EPSS
1%p65
Published
()
Modified
Description

A path traversal via the iniFile parameter in excel.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to download arbitrary files from the host machine.

Vendors
blaauwproducts
Products
remote kiln control
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.