Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2018-15133

Quick assessment

Affected
n/a n/a
Exploitation
Confirmed exploitation in the wild; remediate immediately
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Laravel framework是软件开发者Taylor Otwell开发的一款基于PHP的Web应用程序开发框架。 Laravel framework 5.5.40及之前版本和5.6.x版本至5.6.29版本中存在安全漏洞。远程攻击者可借助应用程序的密钥利用该漏洞执行代码。

AI Predicted 8.1 Difficulty: Easy KEV EPSS 76.81% · P100
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2018-15133

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illuminate/Encryption/Encrypter.php and PendingBroadcast in gadgetchains/Laravel/RCE/3/chain.php in phpggc. The attacker must know the application key, which normally would never occur, but could happen if the attacker previously had privileged access or successfully accomplished a previous attack.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Laravel Framework 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Laravel framework是软件开发者Taylor Otwell开发的一款基于PHP的Web应用程序开发框架。 Laravel framework 5.5.40及之前版本和5.6.x版本至5.6.29版本中存在安全漏洞。远程攻击者可借助应用程序的密钥利用该漏洞执行代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2018-15133

# POC Description Source Link Shenlong Link
1 PoC for CVE-2018-15133 (Laravel unserialize vulnerability) https://github.com/kozmic/laravel-poc-CVE-2018-15133 POC Details
2 Cette exploit en python va vous permettre de créer des listes de sites et les exploiter rapidement. https://github.com/Bilelxdz/Laravel-CVE-2018-15133 POC Details
3 Laravel-PHP-Unit-RCE (CVE-2018-15133) Auto Exploiter and Shell Uploader https://github.com/Prabesh01/Laravel-PHP-Unit-RCE-Auto-shell-uploader POC Details
4 CVE-2018-15133 (Webased) https://github.com/bukitbarisan/laravel-rce-cve-2018-15133 POC Details
5 An automated PoC for CVE 2018-15133 https://github.com/AlienX2001/better-poc-for-CVE-2018-15133 POC Details
6 Exploit for Laravel Remote Code Execution with API_KEY (CVE-2018-15133) https://github.com/aljavier/exploit_laravel_cve-2018-15133 POC Details
7 Laravel RCE exploit. CVE-2018-15133 https://github.com/pwnedshell/Larascript POC Details
8 None https://github.com/AzhariKun/CVE-2018-15133 POC Details
9 "Lavel Exploit CVE-2018-15133 is a powerful exploit that allows attackers to gain unauthorized access to vulnerable systems. This exploit was originally developed as part of a Capture The Flag (CTF) challenge and has since been used by security researchers and ethical hackers to identify and address vulnerabilities in web applications. https://github.com/NatteeSetobol/CVE-2018-15133-Lavel-Expliot POC Details
10 None https://github.com/0xSalle/cve-2018-15133 POC Details
11 None https://github.com/yeahhbean/Laravel-CVE-2018-15133 POC Details
12 None https://github.com/Loaxert/CVE-2018-15133-PoC POC Details
13 Reproducible Docker lab for CVE-2018-15133 (Laravel Framework token unserialize RCE) https://github.com/flame-11/CVE-2018-15133-laravel-framework POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2018-15133

登录查看更多情报信息。

Exploits & Public PoCs for CVE-2018-15133 (1)

Other References for CVE-2018-15133 (1)

Same Patch Batch · n/a · 2018-08-09 · 7 CVEs total

CVE-2018-0429 Cisco Thor decoder 缓冲区错误漏洞
CVE-2018-14735 Hitachi Command Suite 安全漏洞
CVE-2018-15181 JioFi 4G Hotspot M2S 安全漏洞
CVE-2018-15182 PHP Scripts Mall Car Rental Script 跨站脚本漏洞
CVE-2018-15183 PHP Scripts Mall Myperfectresume/JobHero/Resume Clone Script 跨站脚本漏洞
CVE-2018-15184 PHP Scripts Mall Naukri/Shine/Jobsite Clone Script 跨站脚本漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2018-15133

No comments yet


Leave a comment