← voltar
CVE-2018-16763

CVE-2018-16763

EPSS 82.9%
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.
Produtos afetados
n/a · n/a
PoCs públicas encontradas28
githubgithub.com/p0dalirius/CVE-2018-16763-FuelCMS-1.4.1-RCE25githubgithub.com/padsalatushal/CVE-2018-167635githubgithub.com/altsun/CVE-2018-16763-FuelCMS-1.4.1-RCE5githubgithub.com/n3m1sys/CVE-2018-16763-Exploit-Python34githubgithub.com/shoamshilo/Fuel-CMS-Remote-Code-Execution-1.4--RCE--3githubgithub.com/h3x0v3rl0rd/CVE-2018-167632githubgithub.com/hikarihacks/CVE-2018-16763-exploit2githubgithub.com/kxisxr/Bash-Script-CVE-2018-167632githubgithub.com/not1cyyy/CVE-2018-167632githubgithub.com/kaxm23/exploit_cms_fuel1githubgithub.com/dinhbaouit/CVE-2018-167631githubgithub.com/saccles/CVE_2018_16763_Proof_of_Concept0githubgithub.com/uwueviee/Fu3l-F1lt3r0githubgithub.com/wizardy0ga/THM-Vulnerability_Capstone-CVE-2018-167630githubgithub.com/BrunoPincho/cve-2018-16763-rust0githubgithub.com/antisecc/CVE-2018-167630githubgithub.com/VitoBonetti/CVE-2018-167630githubgithub.com/ArtemCyberLab/Project-Exploiting-a-Vulnerability-in-Fuel-CMS-CVE-2018-16763-0githubgithub.com/bad-c0de/CVE-2018-16763_FuelCMS-1.4.1_RCE0githubgithub.com/Cyberuser-hash/CVE-2018-167630githubgithub.com/estebanzarate/CVE-2018-16763-Fuel-CMS-1.4.1-Remote-Code-Execution-PoC0githubgithub.com/SOME-1HING/CVE-2018-167630cve_referencepacketstormsecurity.com/files/153696/fuelCMS-1.4.1-Remote-Code-Execution.htmlnão verificadocve_referencepacketstormsecurity.com/files/164756/Fuel-CMS-1.4.1-Remote-Code-Execution.htmlnão verificadocve_referencewww.exploit-db.com/exploits/47138não verificadoexploitdbwww.exploit-db.com/exploits/49487não verificadoexploitdbwww.exploit-db.com/exploits/50477não verificadocve_referencepacketstormsecurity.com/files/160080/Fuel-CMS-1.4-Remote-Code-Execution.htmlnão verificado
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →