CVE-2019-25024

OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service parameter.
References
Link Resource
https://github.com/OpenRepeater/openrepeater/issues/66 Exploit Third Party Advisory
https://github.com/codexlynx/CVE-2019-25024 Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:alleghenycreative:openrepeater:*:*:*:*:*:*:*:*

Information

Published : 2021-02-18 20:15

Updated : 2021-02-24 12:16


NVD link : CVE-2019-25024

Mitre link : CVE-2019-25024


JSON object : View

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Advertisement

dedicated server usa

Products Affected

alleghenycreative

  • openrepeater