CVE-2019-11447
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. There is no effective control of $imgsize in /core/modules/dashboard.php. The header content of a file can be changed and the control can be bypassed for code execution. (An attacker can use the GIF header for this.)
- Affected products
- Cutenews
- Cutephp Cutenews
- = 2.1.2
- Fix
- Available
- CVSS 3.0
- 8.8 HIGH
- EPSS
- 52.3% (99th percentile)
- Weakness
- CWE-434
- NVD status
- Modified
- Published
- 2019-04-22
CVE-2019-11447 at NVD
18 known exploits for CVE-2019-11447
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2019-11447_reverse_shell_upload
CVE-2019-11447_CuteNews-AvatarUploadRCE
cve-2019-11447
CVE-2019-11447
CVE-2019-11447-POC
WordPress-Path-Traversal-CVE-2019-11447
CVE-2019-11447-EXP
Exploit for Unrestricted Upload of File with Dangerous Type in Cutephp Cutenews
Exploit for Unrestricted Upload of File with Dangerous Type in Cutephp Cutenews
CuteNews 2.1.2 Shell Upload Exploit
Exploit for Unrestricted Upload of File with Dangerous Type in Cutephp Cutenews
CuteNews 2.1.2 Shell Upload
Exploit for Unrestricted Upload of File with Dangerous Type in Cutephp Cutenews
Exploit for Unrestricted Upload of File with Dangerous Type in Cutephp Cutenews
Exploit for Unrestricted Upload of File with Dangerous Type in Cutephp Cutenews
CuteNews 2.1.2 - Remote Code Execution
CuteNews 2.1.2 Remote Code Execution
CuteNews 2.1.2 - 'avatar' Remote Code Execution (Metasploit)