CVE-2019-13372

CVE-2019-13372

/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to execute arbitrary PHP code via a cookie because a cookie’s username field allows eval injection, and an empty password bypasses authentication.

Source: CVE-2019-13372

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다