PT-2018-14819 · Phpcms · Phpcms

Ab1Gale

·

Published

2018-11-09

·

Updated

2019-02-04

·

CVE-2018-19127

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHPCMS 2008
Description A code injection issue in the /type.php file allows attackers to execute arbitrary code by writing PHP code to a cache file with a controllable filename. The PHP code is sent via the template parameter and is written to a data/cache template/*.tpl.php file, which includes a "<?php function " substring.
Recommendations For PHPCMS 2008, as a temporary workaround, consider restricting access to the /type.php file and the template parameter to minimize the risk of exploitation. Avoid using the template parameter in the affected /type.php file until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-19127

Affected Products

Phpcms