The HTTP API in Prismview System 9 11.10.17.00 and Prismview Player 11 13.09.1100 allows remote code execution by uploading RebootSystem.lnk and requesting /REBOOTSYSTEM or /RESTARTVNC. (Authentication is required but an XML file containing credentials can be downloaded.)
References
Link Resource
https://www.exploit-db.com/papers/47535 Exploit Third Party Advisory VDB Entry
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-02-10T14:39:06

Updated: 2020-02-10T14:39:06

Reserved: 2020-02-10T00:00:00


Link: CVE-2019-20451

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-02-10T15:15:21.433

Modified: 2021-09-09T17:41:35.163


Link: CVE-2019-20451

JSON object: View

cve-icon Redhat Information

No data.

CWE