Amine Taouirsa

3 exploits Active since May 2018
CVE-2018-6410 EXPLOITDB CRITICAL text WORKING POC
MachForm - SQL Injection via Download Page q Parameter
An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.
CVSS 9.8
CVE-2018-6409 EXPLOITDB MEDIUM text WORKING POC
MachForm < 4.2.3 - Path Traversal via download.php q Parameter
An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path from the database. Modifying the name of the file to serve on the corresponding ap_form table leads to a path traversal vulnerability via the download.php q parameter.
CVSS 5.3
CVE-2018-6411 EXPLOITDB CRITICAL text WORKING POC
MachForm - Unrestricted Upload of File with Dangerous Type via SQL Injection in ap_form_elements
An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to the filters. If the filter is set to a whitelist, the dangerous extensions can be bypassed through ap_form_elements SQL Injection.
CVSS 9.8