CVE-2019-10863: Code Injection
Published Apr 4, 2019
·Updated
A command injection vulnerability exists in TeemIp versions before 2.4.0. The newconfig parameter of exec.php allows one to create a new PHP file with the exception of config information. The malicious PHP code sent is executed instantaneously and is not saved on the server.
Affected Software
1 affected component
Combodo Teemip<2.4.0
Remediation
Patch Available
Event History
Apr 4, 2019
CVE Published
via MITRE·05:07 PM
Data Sourced
via MITRE·05:07 PM
Description
Frequently Asked Questions
1
What is CVE-2019-10863?
CVE-2019-10863 is a command injection vulnerability in TeemIp versions before 2.4.0.
2
How does CVE-2019-10863 impact TeemIp?
CVE-2019-10863 allows an attacker to execute malicious PHP code instantaneously.
3
What is the severity of CVE-2019-10863?
CVE-2019-10863 has a severity rating of 7.2 (High).
4
How can I fix CVE-2019-10863?
To fix CVE-2019-10863, update your TeemIp installation to version 2.4.0 or above.
5
Are there any known exploits for CVE-2019-10863?
Yes, there are exploits available for CVE-2019-10863. Be cautious and update your software to protect against them.