CVE-2019-9623: Malicious File Upload
Published Mar 7, 2019
·Updated
Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ckuploadhandler.php.
Affected Software
1 affected component
Fengoffice Feng Office=3.7.0.5
Event History
Mar 7, 2019
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Data Sourced
via NVD·05:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-9623?
CVE-2019-9623 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2019-9623?
To fix CVE-2019-9623, upgrade Feng Office to a version that is not vulnerable, typically a version later than 3.7.0.5.
3
What kind of attack does CVE-2019-9623 allow?
CVE-2019-9623 allows remote attackers to execute arbitrary code through a specific command injection vulnerability.
4
In which software is CVE-2019-9623 found?
CVE-2019-9623 is found in Feng Office version 3.7.0.5.
5
Is user authentication required to exploit CVE-2019-9623?
No, CVE-2019-9623 can be exploited by unauthenticated remote attackers.