mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-29 09:41:05 +00:00
19 lines
872 B
Markdown
19 lines
872 B
Markdown
![]() |
### [CVE-2019-11508](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11508)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an authenticated attacker (via the admin web interface) can exploit Directory Traversal to execute arbitrary code on the appliance.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- https://devco.re/blog/2019/09/02/attacking-ssl-vpn-part-3-the-golden-Pulse-Secure-ssl-vpn-rce-chain-with-Twitter-as-case-study/
|
||
|
- https://kb.pulsesecure.net/?atype=sa
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/jaychouzzk/Pulse-Secure-SSL-VPN-CVE-2019
|
||
|
|