mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-07 19:16:22 +00:00
19 lines
849 B
Markdown
19 lines
849 B
Markdown
![]() |
### [CVE-2019-7323](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7323)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
GUP (generic update process) in LightySoft LogMX before 7.4.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update. The update process relies on cleartext HTTP. The attacker could replace the LogMXUpdater.class file.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- https://bmantra.github.io/logmx/logmx.html
|
||
|
- https://github.com/bmantra/bmantra.github.io/blob/master/logmx/logmx.html
|
||
|
|
||
|
#### Github
|
||
|
No PoCs found on GitHub currently.
|
||
|
|