CVE-2019-10863
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
04/04/2019
Last modified:
24/08/2020
Description
A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows one to create a new PHP file with the exception of config information. The malicious PHP code sent is executed instantaneously and is not saved on the server.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:combodo:teemip:*:*:*:*:*:*:*:* | 2.4.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



