CVE-2018-19422
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these.
- Affected products
- Subrion Cms
- Intelliants Subrion Cms
- = 4.2.1
- Fix
- Available
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 64.3% (99th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2018-11-21
CVE-2018-19422 at NVD
13 known exploits for CVE-2018-19422
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2018-19422-SubrionCMS-RCE
SubrionCMS-4.2.1-File-upload-RCE-auth-
CVE-2018-19422
Intelliants Subrion CMS 4.2.1 Remote Code Execution Exploit
Intelliants Subrion CMS 4.2.1 Remote Code Execution
Exploit for Unrestricted Upload of File with Dangerous Type in Intelliants Subrion_Cms
FUSE - A Penetration Testing Tool For Finding File Upload Bugs
Exploit for Unrestricted Upload of File with Dangerous Type in Intelliants Subrion_Cms
Exploit for Unrestricted Upload of File with Dangerous Type in Intelliants Subrion_Cms
Subrion CMS 4.2.1 - File Upload Bypass to RCE (Authenticated) Exploit
Subrion CMS 4.2.1 - Arbitrary File Upload
Subrion CMS 4.2.1 Shell Upload
Intelliants Subrion CMS 4.2.1 - Authenticated File Upload Bypass to RCE