Description
FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' parameters.
Problem types
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
5.7.2 build 568
5.7.0 build 539
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5523.php
www.exploit-db.com/exploits/47064 (ExploitDB-47064)
www.iwt.com.hk (Official Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5523.php (Zero Science Lab Disclosure (ZSL-2019-5523))
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.