CVE-2019-10863

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
04/04/2019
Last modified:
24/08/2020

Description

A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows one to create a new PHP file with the exception of config information. The malicious PHP code sent is executed instantaneously and is not saved on the server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:combodo:teemip:*:*:*:*:*:*:*:* 2.4.0 (excluding)