Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 
 
 
 
 

Repository files navigation

CVE-2018-19422-SubrionCMS-RCE

SubrionCMS 4.2.1 Authenticated Remote Code Execution

  • /panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these.

Exploit Usage

Commands:

  • Windows/Linux: $ sudo python3 subrionRCE.py -u http://IP/panel/ -l <user> -p <password>

About

CVE-2018-19422 Authenticated Remote Code Execution

Resources

Stars

8 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages