CVE-2019-7751

HIGH

Ricoh MarcomCentral - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-7751. PoCs published by 0v3rride.

AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in MarcomCentral FusionPro VDP Creator < 10.0, allowing remote attackers to read sensitive files by sending a crafted HTTP request to the FPProducerInternetServer.exe service. The PoC uses the `requests` library to fetch arbitrary files from the target system.

Description

A directory traversal and local file inclusion vulnerability in FPProducerInternetServer.exe in Ricoh MarcomCentral, formerly PTI Marketing, FusionPro VDP before 10.0 allows a remote attacker to list or enumerate sensitive contents of files. Furthermore, this could allow for privilege escalation by dumping the local machine's SAM and SYSTEM database files, and possibly remote code execution.

Exploits (1)

exploitdb WORKING POC
by 0v3rride · pythonwebappswindows
https://www.exploit-db.com/exploits/46494

This exploit demonstrates a directory traversal vulnerability in MarcomCentral FusionPro VDP Creator < 10.0, allowing remote attackers to read sensitive files by sending a crafted HTTP request to the FPProducerInternetServer.exe service. The PoC uses the `requests` library to fetch arbitrary files from the target system.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: MarcomCentral FusionPro VDP Creator < 10.0
No auth needed
Prerequisites: Network access to the target service (default port 8080) · FPProducerInternetServer.exe running on the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/46494

Scores

CVSS v3 7.5
EPSS 0.1421
EPSS Percentile 96.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (1)
ricoh/fusionpro_vdp < 10.0
Published Dec 31, 2019
Tracked Since Feb 18, 2026