CVE-2019-16951
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A remote file include (RFI) issue was discovered in Enghouse Web Chat 6.2.284.34. One can replace the localhost attribute with one's own domain name. When the product calls this domain after the POST request is sent, it retrieves an attacker's data and displays it. Also worth mentioning is the amount of information sent in the request from this product to the attacker: it reveals information the public should not have. This includes pathnames and internal ip addresses.
Se descubrió un problema de tipo remote file include (RFI) en Enghouse Web Chat versión 6.2.284.34. Uno puede reemplazar el atributo localhost con un nombre de dominio propio. Cuando el producto llama a este dominio luego que se envía la petición POST, recupera los datos de un atacante y los muestra. También vale la pena mencionar la cantidad de información enviada en la petición desde este producto hacia un atacante: revela información que el público no debería tener. Esto incluye nombres de ruta y direcciones IP internas.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-09-29 CVE Reserved
- 2019-11-13 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-829: Inclusion of Functionality from Untrusted Control Sphere
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://mjlanders.com/2019/11/07/multiple-vulnerabilities-found-in-enghouse-zeacom-web-chat | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Enghouse Search vendor "Enghouse" | Web Chat Search vendor "Enghouse" for product "Web Chat" | 6.1.300.31 Search vendor "Enghouse" for product "Web Chat" and version "6.1.300.31" | - |
Affected
| ||||||
Enghouse Search vendor "Enghouse" | Web Chat Search vendor "Enghouse" for product "Web Chat" | 6.2.284.34 Search vendor "Enghouse" for product "Web Chat" and version "6.2.284.34" | - |
Affected
|