CVE-2019-4013
CRITICALIBM BigFix Platform 9.5.0-9.5.10 - Authenticated Arbitrary File Upload and Remote Code Execution
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-4013. PoCs published by Jakub Palaczynski.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in IBM Bigfix Platform <= 9.5.9.62, allowing authenticated users to upload files to any location on the server with root privileges via path traversal in the 'urlFileName' parameter.
Description
IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root privileges. This results in code execution on underlying system with root privileges. IBM X-Force ID: 155887.
Exploits (1)
This exploit demonstrates an arbitrary file upload vulnerability in IBM Bigfix Platform <= 9.5.9.62, allowing authenticated users to upload files to any location on the server with root privileges via path traversal in the 'urlFileName' parameter.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H