In IXP EasyInstall 6.2.13723, there is Directory Traversal on TCP port 8000 via the Engine Service by an unauthenticated attacker, who can access the server's filesystem with the access rights of NT AUTHORITY\SYSTEM.
References
Link | Resource |
---|---|
https://improsec.com/tech-blog/multiple-vulnerabilities-in-easyinstall-rmm-and-deployment-software | Exploit Third Party Advisory |
https://improsec.com/tech-blog/multiple-vulnerabilities-in-easyinstall-rmm-and-deployment-software | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 04:35
Type | Values Removed | Values Added |
---|---|---|
References | () https://improsec.com/tech-blog/multiple-vulnerabilities-in-easyinstall-rmm-and-deployment-software - Exploit, Third Party Advisory |
Information
Published : 2020-01-23 21:15
Updated : 2024-11-21 04:35
NVD link : CVE-2019-19893
Mitre link : CVE-2019-19893
CVE.ORG link : CVE-2019-19893
JSON object : View
Products Affected
ixpdata
- easyinstall
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')