CVE-2019-16113
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 78%
from disclosure to weapon73 days
Published on NVDSep 8
1st PoC+73d
metasploitSep 7
exploitation probability
78%top 1% of all CVEs
observed exploitation
nono source reports it
15 public exploit(s)
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PHP code can write other PHP code to a ../ pathname.
Affected products
n/a · n/apublic PoCs found — 15✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/47699exploitdbwww.exploit-db.com/exploits/48568unverifiedexploitdbwww.exploit-db.com/exploits/48701unverifiedgithubgithub.com/cybervaca/CVE-2019-16113★ 13githubgithub.com/hg8/CVE-2019-16113-PoC★ 5githubgithub.com/ynots0ups/CVE-2019-16113★ 5githubgithub.com/mind2hex/CVE-2019-16113-Bludit-3.9.2-RCE★ 1githubgithub.com/m4rm0k/CVE-2019-16113★ 0githubgithub.com/DXY0411/CVE-2019-16113★ 0githubgithub.com/tronghoang89/cve-2019-16113★ 0githubgithub.com/Kenun99/CVE-2019-16113-Dockerfile★ 0githubgithub.com/dldygnl/CVE-2019-16113★ 0cve_referencepacketstormsecurity.com/files/157988/Bludit-3.9.12-Directory-Traversal.htmlunverifiedcve_referencepacketstormsecurity.com/files/155295/Bludit-Directory-Traversal-Image-File-Upload.htmlunverifiedcve_referencepacketstormsecurity.com/files/158569/Bludit-3.9.2-Directory-Traversal.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/155295/Bludit-Directory-Traversal-Image-File-Upload.htmlhttp://packetstormsecurity.com/files/157988/Bludit-3.9.12-Directory-Traversal.htmlhttp://packetstormsecurity.com/files/158569/Bludit-3.9.2-Directory-Traversal.htmlhttps://github.com/bludit/bludit/issues/1081