Subrion CMS是Subrion团队开发的一套基于PHP的内容管理系统(CMS)。该系统可被集成到网站,并支持多种扩展插件等。 Subrion CMS 4.2.1版本中的/panel/uploads存在安全漏洞,该漏洞源于.htaccess文件没有禁止对pht和phar文件的执行操作。远程攻击者可借助.pht或.phar文件利用该漏洞执行任意的PHP代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2018-19422 Authenticated Remote Code Execution | https://github.com/h3v0x/CVE-2018-19422-SubrionCMS-RCE | POC Details |
| 2 | This is an edited version of the CVE-2018-19422 exploit to fix an small but annoying issue I had. | https://github.com/Swammers8/SubrionCMS-4.2.1-File-upload-RCE-auth- | POC Details |
| 3 | CVE-2018-19422 Authenticated Remote Code Execution | https://github.com/hev0x/CVE-2018-19422-SubrionCMS-RCE | POC Details |
| 4 | Subrion File Upload Bypass to RCE and Custom File Upload (Authenticated) | https://github.com/Drew-Alleman/CVE-2018-19422 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2018-19420 | Cagintranet GetSimple CMS 安全漏洞 | |
| CVE-2018-19421 | Cagintranet GetSimple CMS 安全漏洞 | |
| CVE-2018-19423 | Codiad 安全漏洞 | |
| CVE-2018-19424 | ClipperCMS 安全漏洞 | |
| CVE-2018-19416 | Sysstat 缓冲区错误漏洞 | |
| CVE-2018-19417 | Contiki-NG MQTT服务器缓冲区错误漏洞 | |
| CVE-2018-19409 | Artifex Ghostscript 安全漏洞 | |
| CVE-2018-19410 | Paessler PRTG Network Monitor 权限许可和访问控制问题漏洞 | |
| CVE-2018-19411 | Paessler PRTG Network Monitor 权限许可和访问控制问题漏洞 | |
| CVE-2009-5153 | Novell NetWare 缓冲区错误漏洞 | |
| CVE-2018-19404 | YXcms 安全漏洞 | |
| CVE-2018-19406 | Linux kernel 安全漏洞 | |
| CVE-2018-19407 | Linux kernel 安全漏洞 |
No comments yet