mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-29 09:41:05 +00:00
24 lines
1.0 KiB
Markdown
24 lines
1.0 KiB
Markdown
![]() |
### [CVE-2018-19127](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19127)
|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a controllable filename, leading to arbitrary code execution. The PHP code is sent via the template parameter, and is written to a data/cache_template/*.tpl.php file along with a "<?php function " substring.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
No PoCs from references.
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/0xT11/CVE-POC
|
||
|
- https://github.com/ARPSyndicate/cvemon
|
||
|
- https://github.com/CVEDB/PoC-List
|
||
|
- https://github.com/CVEDB/awesome-cve-repo
|
||
|
- https://github.com/SexyBeast233/SecBooks
|
||
|
- https://github.com/ab1gale/phpcms-2008-CVE-2018-19127
|
||
|
- https://github.com/zhibx/fscan-Intranet
|
||
|
|