CVE-2019-11447
CVE-2019-11447
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. There is no effective control of $imgsize in /core/modules/dashboard.php. The header content of a file can be changed and the control can be bypassed for code execution. (An attacker can use the GIF header for this.)
Productos afectados
n/a · n/aPoCs públicas encontradas — 10
githubgithub.com/thewhiteh4t/cve-2019-11447★ 9githubgithub.com/CRFSlick/CVE-2019-11447-POC★ 1githubgithub.com/khuntor/CVE-2019-11447-EXP★ 1githubgithub.com/substing/CVE-2019-11447_reverse_shell_upload★ 0githubgithub.com/mt-code/CVE-2019-11447★ 0githubgithub.com/ColdFusionX/CVE-2019-11447_CuteNews-AvatarUploadRCE★ 0exploitdbwww.exploit-db.com/exploits/48800no verificadocve_referencewww.exploit-db.com/exploits/46698/no verificadoexploitdbwww.exploit-db.com/exploits/46698no verificadocve_referencepacketstormsecurity.com/files/159134/CuteNews-2.1.2-Remote-Code-Execution.htmlno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →