CVE-2019-16113
CVE-2019-16113
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PHP code can write other PHP code to a ../ pathname.
Produtos afetados
n/a · n/aPoCs públicas encontradas — 15
githubgithub.com/cybervaca/CVE-2019-16113★ 13githubgithub.com/hg8/CVE-2019-16113-PoC★ 5githubgithub.com/ynots0ups/CVE-2019-16113★ 5githubgithub.com/mind2hex/CVE-2019-16113-Bludit-3.9.2-RCE★ 1githubgithub.com/DXY0411/CVE-2019-16113★ 0githubgithub.com/m4rm0k/CVE-2019-16113★ 0githubgithub.com/tronghoang89/cve-2019-16113★ 0githubgithub.com/Kenun99/CVE-2019-16113-Dockerfile★ 0githubgithub.com/dldygnl/CVE-2019-16113★ 0exploitdbwww.exploit-db.com/exploits/48568não verificadocve_referencepacketstormsecurity.com/files/157988/Bludit-3.9.12-Directory-Traversal.htmlnão verificadocve_referencepacketstormsecurity.com/files/158569/Bludit-3.9.2-Directory-Traversal.htmlnão verificadoexploitdbwww.exploit-db.com/exploits/48701não verificadoexploitdbwww.exploit-db.com/exploits/47699não verificadocve_referencepacketstormsecurity.com/files/155295/Bludit-Directory-Traversal-Image-File-Upload.htmlnão verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://packetstormsecurity.com/files/155295/Bludit-Directory-Traversal-Image-File-Upload.htmlhttp://packetstormsecurity.com/files/157988/Bludit-3.9.12-Directory-Traversal.htmlhttp://packetstormsecurity.com/files/158569/Bludit-3.9.2-Directory-Traversal.htmlhttps://github.com/bludit/bludit/issues/1081