ZeroHour

CVE-2019-18871

PoC
CVSS 3.1
8.8 high
EPSS
3%p84
Published
()
Modified
Description

A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to upload arbitrary files, leading to arbitrary remote code execution.

Vendors
blaauwproducts
Products
remote kiln control
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.