CVE-2018-5749
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
install.php in Minecraft Servers List Lite before commit c1cd164 and Premium Minecraft Servers List before 2.0.4 does not sanitize input before saving database connection information in connect.php, which might allow remote attackers to execute arbitrary PHP code via the (1) database_server, (2) database_user, (3) database_password, or (4) database_name parameter.
install.php en Minecraft Servers List Lite antes del commit con ID c1cd164 y Premium Minecraft Servers List en versiones anteriores a la 2.0.4 no sanea las entradas antes de guardar la información de conexión de base de datos en connect.php. Esto podría permitir que atacantes remotos ejecuten código PHP arbitrario mediante los parámetros (1) database_server, (2) database_user, (3) database_password o (4) database_name.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-01-17 CVE Reserved
- 2018-01-23 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.rastating.com/minecraft-servers-list-unauthenticated-shell-upload | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Premium Minecraft Servers List Project Search vendor "Premium Minecraft Servers List Project" | Premium Minecraft Servers List Search vendor "Premium Minecraft Servers List Project" for product "Premium Minecraft Servers List" | < 2.0.4 Search vendor "Premium Minecraft Servers List Project" for product "Premium Minecraft Servers List" and version " < 2.0.4" | - |
Affected
| ||||||
Minecraft Servers List Lite Project Search vendor "Minecraft Servers List Lite Project" | Minecraft Servers List Lite Search vendor "Minecraft Servers List Lite Project" for product "Minecraft Servers List Lite" | < 1.1 Search vendor "Minecraft Servers List Lite Project" for product "Minecraft Servers List Lite" and version " < 1.1" | - |
Affected
|