CVE-2019-25468

NetGain EM Plus 10.1.68 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious parameters to the script_test.jsp endpoint. Attackers can send POST requests with shell commands embedded in the 'content' parameter to execute code and retrieve command output.
Configurations

No configuration.

History

11 Mar 2026, 22:16

Type Values Removed Values Added
References
  • {'url': 'https://www.vulncheck.com/advisories/netgain-em-plus-remote-code-execution-via-script-testjsp', 'source': 'disclosure@vulncheck.com'}
  • () https://www.vulncheck.com/advisories/netgain-em-plus-remote-code-execution-via-script-test-jspĀ -

11 Mar 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-11 19:16

Updated : 2026-03-12 21:08


NVD link : CVE-2019-25468

Mitre link : CVE-2019-25468

CVE.ORG link : CVE-2019-25468


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')