Critical severity9.8OSV Advisory· Published Mar 7, 2019· Updated Jun 17, 2026
CVE-2019-9623
CVE-2019-9623
Description
Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
23.6.0RC1, 3.6.3-rc7, 3.6.3.5, …+ 1 more
- (no CPE)range: 3.6.0RC1, 3.6.3-rc7, 3.6.3.5, …
- (no CPE)range: = 3.7.0.5
Patches
Vulnerability mechanics
References
2- pentest.com.tr/exploits/Feng-Office-3-7-0-5-Unauthenticated-Remote-Command-Execution-Metasploit.htmlnvdExploitThird Party Advisory
- www.exploit-db.com/exploits/46471nvdExploitThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.