#VU16207 OS command injection in PRTG Network Monitor - CVE-2018-19204
Published: December 3, 2018
PRTG Network Monitor
Paessler AG
Description
The vulnerability allows a remote high-privileged attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to the user's input in the POST parameter 'proxyport_' is mishandled when creating an HTTP Advanced Sensor. A remote attacker can craft an HTTP request and override the 'writeresult' command-line parameter for HttpAdvancedSensor.exe and store arbitrary data in an arbitrary place on the file system to create an executable file in the Custom SensorsEXE directory and execute it by creating EXE/Script Sensor.