CVE-2019-16113
CVE-2019-16113
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PHP code can write other PHP code to a ../ pathname.
Productos afectados
n/a · n/aPoCs públicas encontradas — 15
githubgithub.com/cybervaca/CVE-2019-16113★ 13githubgithub.com/hg8/CVE-2019-16113-PoC★ 5githubgithub.com/ynots0ups/CVE-2019-16113★ 5githubgithub.com/mind2hex/CVE-2019-16113-Bludit-3.9.2-RCE★ 1githubgithub.com/DXY0411/CVE-2019-16113★ 0githubgithub.com/m4rm0k/CVE-2019-16113★ 0githubgithub.com/tronghoang89/cve-2019-16113★ 0githubgithub.com/Kenun99/CVE-2019-16113-Dockerfile★ 0githubgithub.com/dldygnl/CVE-2019-16113★ 0exploitdbwww.exploit-db.com/exploits/48568no verificadocve_referencepacketstormsecurity.com/files/157988/Bludit-3.9.12-Directory-Traversal.htmlno verificadocve_referencepacketstormsecurity.com/files/158569/Bludit-3.9.2-Directory-Traversal.htmlno verificadoexploitdbwww.exploit-db.com/exploits/48701no verificadoexploitdbwww.exploit-db.com/exploits/47699no verificadocve_referencepacketstormsecurity.com/files/155295/Bludit-Directory-Traversal-Image-File-Upload.htmlno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://packetstormsecurity.com/files/155295/Bludit-Directory-Traversal-Image-File-Upload.htmlhttp://packetstormsecurity.com/files/157988/Bludit-3.9.12-Directory-Traversal.htmlhttp://packetstormsecurity.com/files/158569/Bludit-3.9.2-Directory-Traversal.htmlhttps://github.com/bludit/bludit/issues/1081