CVE-2018-19422: Unrestricted Upload of File with Dangerous Type
(updated )
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these.
References
- packetstormsecurity.com/files/162591/Subrion-CMS-4.2.1-Shell-Upload.html
- packetstormsecurity.com/files/173998/Intelliants-Subrion-CMS-4.2.1-Remote-Code-Execution.html
- github.com/advisories/GHSA-73xj-v6gc-g5p5
- github.com/intelliants/subrion/commit/74359bcfaea424edda6d782a8ac25397c55972ab
- github.com/intelliants/subrion/issues/801
- nvd.nist.gov/vuln/detail/CVE-2018-19422
Detect and mitigate CVE-2018-19422 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →