← Back

CVE-2018-19196

nvd nist
Published: Nov 12, 2018Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An issue was discovered in XiaoCms 20141229. It allows remote attackers to execute arbitrary code by using the type parameter to bypass the standard admin\controller\uploadfile.php restrictions on uploaded file types (jpg, jpeg, bmp, png, gif), as demonstrated by an admin/index.php?c=uploadfile&a=uploadify_upload&type=php URI.

Affected (1)

Products: Xiaocms: Xiaocms
1 product
Xiaocms
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 20141229

References (4)

Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory

Timeline

No history available yet.