CVE-2018-19458
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 33%
from disclosure to weapon0 days
Published on NVDNov 22
1st PoCNov 5
exploitation probability
33%top 2% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI URI, a different vulnerability than CVE-2018-19246.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/45780unverifiedcve_referencewww.exploit-db.com/exploits/45780/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.