The HTTP API in Prismview System 9 11.10.17.00 and Prismview Player 11 13.09.1100 allows remote code execution by uploading RebootSystem.lnk and requesting /REBOOTSYSTEM or /RESTARTVNC. (Authentication is required but an XML file containing credentials can be downloaded.)
References
Link | Resource |
---|---|
https://www.exploit-db.com/papers/47535 | Exploit Third Party Advisory VDB Entry |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-02-10T14:39:06
Updated: 2020-02-10T14:39:06
Reserved: 2020-02-10T00:00:00
Link: CVE-2019-20451
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-02-10T15:15:21.433
Modified: 2021-09-09T17:41:35.163
Link: CVE-2019-20451
JSON object: View
Redhat Information
No data.
CWE