CVE-2018-9206
84Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 97%
from disclosure to weapon0 days
Published on NVDOct 11
1st PoCOct 11
metasploitOct 9
VulnCheckMay 9
exploitation probability
97%top 1% of all CVEs
observed exploitation
yesVulnCheck
16 public exploit(s)
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
Affected products
Blueimp · Blueimp jQuery-File-Uploadpublic PoCs found — 16✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/45790exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/45584exploitdbwww.exploit-db.com/exploits/46182unverifiedgithubgithub.com/Stahlz/JQShell★ 62githubgithub.com/Den1al/CVE-2018-9206★ 13githubgithub.com/flame-11/CVE-2018-9206-jquery-file-upload★ 1githubgithub.com/liemkaka/CVE-2018-9206★ 0githubgithub.com/mi-hood/CVE-2018-9206★ 0githubgithub.com/cved-sources/cve-2018-9206★ 0cve_referencewww.exploit-db.com/exploits/46182/unverifiedvulncheckvulncheck.com/xdb/e812f9642840unverifiedvulncheckvulncheck.com/xdb/686936ca9734unverifiedvulncheckvulncheck.com/xdb/5d74a3e92db3unverifiedvulncheckvulncheck.com/xdb/157694709091unverifiedvulncheckvulncheck.com/xdb/4c45e2493329unverifiedcve_referencewww.exploit-db.com/exploits/45790/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://wpvulndb.com/vulnerabilities/9136https://www.exploit-db.com/exploits/45790/https://www.exploit-db.com/exploits/46182/https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttp://www.securityfocus.com/bid/105679http://www.securityfocus.com/bid/106629http://www.vapidlabs.com/advisory.php?v=204