VYPR
Critical severity9.8OSV Advisory· Published Mar 7, 2019· Updated Jun 17, 2026

CVE-2019-9623

CVE-2019-9623

Description

Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Fengoffice/FengofficeOSV3 versions
    3.6.0RC1, 3.6.3-rc7, 3.6.3.5, …+ 2 more
    • (no CPE)range: 3.6.0RC1, 3.6.3-rc7, 3.6.3.5, …
    • cpe:2.3:a:fengoffice:feng_office:3.7.0.5:*:*:*:*:*:*:*
    • (no CPE)range: = 3.7.0.5

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.