← All CVEs

CVE-2018-17936

critical · 9.8

NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files to the server, which could allow remote code execution.

9.8
CVSS
15.3%
EPSS (exploit prob.)
97th
EPSS percentile
2018-11-27
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-434

Affected products

VendorProductAffected versions
nuuonuuo_cms<= 3.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-17936