PHPCMS是一套基于PHP和Mysql架构的网站内容管理系统。该系统包括新闻、图片、下载、信息、产品等模块。 PHPCMS 2008版本中存在代码注入漏洞。攻击者可借助‘template’参数利用该漏洞向网站缓存中写入任意内容,执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/ab1gale/phpcms-2008-CVE-2018-19127 | POC Details |
| 2 | None | https://github.com/chaitin/xray-plugins/blob/main/poc/manual/phpcms-cve-2018-19127.yml | POC Details |
| 3 | PHPCMS 2008 suffers from an unauthenticated RCE via template injection in type.php, where attacker-supplied content is written into a PHP template cache file, which is then executable. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-19127.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2018-19124 | PrestaShop for Windows 路径遍历漏洞 | |
| CVE-2018-19133 | Flarum Core 安全漏洞 | |
| CVE-2018-19132 | Squid 安全漏洞 | |
| CVE-2018-19131 | Squid 跨站脚本漏洞 | |
| CVE-2018-19130 | Libav 缓冲区错误漏洞 | |
| CVE-2018-19129 | Libav 安全漏洞 | |
| CVE-2018-19128 | Libav 缓冲区错误漏洞 | |
| CVE-2018-19126 | PrestaShop 安全漏洞 | |
| CVE-2018-19125 | PrestaShop 安全漏洞 | |
| CVE-2018-19145 | S-CMS 跨站脚本漏洞 | |
| CVE-2018-19122 | libIEC61850 安全漏洞 | |
| CVE-2018-19121 | libIEC61850 安全漏洞 | |
| CVE-2018-19137 | DomainMod 跨站脚本漏洞 | |
| CVE-2018-19136 | DomainMOD 跨站脚本漏洞 | |
| CVE-2018-19139 | JasPer 资源管理错误漏洞 | |
| CVE-2018-19138 | WSTMart 跨站请求伪造漏洞 | |
| CVE-2018-17612 | Sennheiser HeadSetup 安全漏洞 |
No comments yet