mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-29 09:41:05 +00:00
19 lines
768 B
Markdown
19 lines
768 B
Markdown
![]() |
### [CVE-2019-12744](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12744)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a different vulnerability than CVE-2018-12940.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- http://packetstormsecurity.com/files/153383/SeedDMS-Remote-Command-Execution.html
|
||
|
- http://packetstormsecurity.com/files/163283/Seeddms-5.1.10-Remote-Command-Execution.html
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/nobodyatall648/CVE-2019-12744
|
||
|
|