CVE-2019-16113
HIGH 8.8EPSS 78.0%
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PHP code can write other PHP code to a ../ pathname.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P - EPSS
- 77.96% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2019-09-08
- Updated
- 2024-08-05
Proof-of-concept exploits (14)
- http://packetstormsecurity.com/files/155295/Bludit-Directory-Traversal-Image-File-Upload.…
- http://packetstormsecurity.com/files/157988/Bludit-3.9.12-Directory-Traversal.html
- http://packetstormsecurity.com/files/158569/Bludit-3.9.2-Directory-Traversal.html
- bludit/bludit/issues/1081
- DXY0411/CVE-2019-161130★ · 2021-02-05
- Kenun99/CVE-2019-16113-Dockerfile0★ · 2020-07-04
- cybervaca/CVE-2019-1611313★ · 2020-06-05
- dldygnl/CVE-2019-161130★ · 2020-09-04
- hg8/CVE-2019-16113-PoC5★ · 2020-06-09
- itsjeffersonli/CVE-2019-161130★ · 2020-09-04
- m4rm0k/CVE-2019-161130★ · 2020-10-03
- mind2hex/CVE-2019-161131★ · 2024-03-28
- mind2hex/CVE-2019-16113-Bludit-3.9.2-RCE1★ · 2024-03-28
- ynots0ups/CVE-2019-161135★ · 2020-06-03
Metasploit modules (1)
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/47699
- https://www.exploit-db.com/exploits/48701
- https://www.exploit-db.com/exploits/48568