CVE-2019-12744
high · 7.5SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a different vulnerability than CVE-2018-12940.
7.5
CVSS
11.7%
EPSS (exploit prob.)
96th
EPSS percentile
2019-06-20
Published
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-434
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| seeddms | seeddms | < 5.1.11 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/153383/SeedDMS-Remote-Command-Execution.html
- http://packetstormsecurity.com/files/163283/Seeddms-5.1.10-Remote-Command-Execution.html
- https://secfolks.blogspot.com/2019/06/exploit-for-cve-2019-12744-remote.html
- https://sourceforge.net/p/seeddms/code/ci/master/tree/CHANGELOG
- http://packetstormsecurity.com/files/153383/SeedDMS-Remote-Command-Execution.html
- http://packetstormsecurity.com/files/163283/Seeddms-5.1.10-Remote-Command-Execution.html
- https://secfolks.blogspot.com/2019/06/exploit-for-cve-2019-12744-remote.html
- https://sourceforge.net/p/seeddms/code/ci/master/tree/CHANGELOG
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-12744