We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2019-18952



Assignermitre
Reserved2019-11-13
Published2019-11-13
Updated2024-08-05

Description

SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execution via a .html file, containing short codes, that is served over HTTP.

References

https://gist.github.com/pak0s/af9f640170aed335fdf6d110d468dbce

http://packetstormsecurity.com/files/155324/Xfilesharing-2.5.1-Local-File-Inclusion-Shell-Upload.html

cve.org CVE-2019-18952

nvd.nist.gov CVE-2019-18952

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2019-18952
Support options

Helpdesk Telegram

Subscribe to our newsletter to learn more about our work.