CVE-2018-20166
Rukovoditel Project Management CRM 2.3.1 - Remote Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a background image, and mishandles extension checking. It accepts uploads of PHP content if the first few characters match GIF data, and the filename ends in ".php" with mixed case, such as the .pHp extension.
Una vulnerabilidad de subida de archivos existe en la versión 2.3.1 de Rukovoditel. index.php?module=configuration/save permite a los usuarios subir una imagen de fondo y, además, maneja incorrectamente la comprobación de extensiones. Acepta la subida de contenido PHP si los primeros caracteres coinciden con los datos GIF y el nombre del archivo termina en ".php" con mayúsculas y minúsculas, como es la extensión .pHp.
Rukovoditel Project Management CRM version 2.3.1 suffers from a remote code execution vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-12-16 CVE Reserved
- 2018-12-19 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-10-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/46011 | 2024-08-05 | |
https://pentest.com.tr/exploits/Rukovoditel-Project-Management-CRM-2-3-1-Authenticated-Remote-Code-Execution.html | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rukovoditel Search vendor "Rukovoditel" | Rukovoditel Search vendor "Rukovoditel" for product "Rukovoditel" | 2.3.1 Search vendor "Rukovoditel" for product "Rukovoditel" and version "2.3.1" | - |
Affected
|