CVE-2017-18048
high · 8.8Monstra CMS 3.0.4 allows users to upload arbitrary files, which leads to remote command execution on the server, for example because .php (lowercase) is blocked but .PHP (uppercase) is not.
8.8
CVSS
63.4%
EPSS (exploit prob.)
99th
EPSS percentile
2018-01-23
Published
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-434
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| monstra | monstra | 3.0.4 |
Check a specific version with /api/v1/cve/match.
References
- https://blogs.securiteam.com/index.php/archives/3559
- https://github.com/monstra-cms/monstra/issues/426
- https://securityprince.blogspot.in/2017/12/monstra-cms-304-arbitrary-file-upload.html
- https://www.exploit-db.com/exploits/43348/
- https://blogs.securiteam.com/index.php/archives/3559
- https://github.com/monstra-cms/monstra/issues/426
- https://securityprince.blogspot.in/2017/12/monstra-cms-304-arbitrary-file-upload.html
- https://www.exploit-db.com/exploits/43348/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-18048