PT-2019-14924 · Ilch · Ilch
4N4Nd
·
Published
2019-09-30
·
Updated
2019-10-04
·
CVE-2019-17046
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Ilch version 2.1.22
Description
The issue allows remote code execution. This is because
php is listed under "Allowed files" on the /admin/media/settings/index page, which can be exploited.Recommendations
For Ilch version 2.1.22, remove
php from the list of "Allowed files" on the /admin/media/settings/index page to prevent remote code execution.Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ilch