CVE-2019-7751 Information

Description

A directory traversal and local file inclusion vulnerability in FPProducerInternetServer.exe in Ricoh MarcomCentral formerly PTI Marketing FusionPro VDP before 10.0 allows a remote attacker to list or enumerate sensitive contents of files. Furthermore this could allow for privilege escalation by dumping the local machine’s SAM and SYSTEM database files and possibly remote code execution.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Reference

https://packetstormsecurity.com/files/151963/MarcomCentral-FusionPro-VDP-Creator-Directory-Traversal.html https://www.exploit-db.com/exploits/46494

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

7.5

Share on: