peter bassill · operator
$ cve CVE-2018-19458 JSON

CVE-2018-19458 EXPLOIT

7.5
HIGH · CVSS 3.0 · EPSS 32.9% (pctl 98)

Patch early

A public exploit exists.

Description

In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI URI, a different vulnerability than CVE-2018-19246.

Scoring

CVSS7.5 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS32.89% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2018-11-22
Last modified2026-06-17

Affected (1)

VendorProduct
php-proxyphp-proxy

Public exploits

SourceTitleDate
exploit-dbPHP Proxy 3.0.3 - Local File Inclusion2018-11-05

References

→ the Explorer  ·  watch your stack  ·  NVD