CVE-2019-25243
FaceSentry 6.4.8 Authenticated Remote Command Injection via Ping Test
FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' parameters.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Produtos afetados
iWT Ltd. · FaceSentry Access Control SystemQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →