CVE-2018-11686
CRITICAL EXPLOITED NUCLEIFlexPaper < 2.3.6 - Remote Code Execution via Publish Service
Title source: llmExploitation Summary
CVE-2018-11686 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including redtimmysec, mpgn. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit targets a remote command execution vulnerability in FlexPaper PHP Publish Service <= 2.3.6. It deletes the target configuration file, uploads a webshell, and provides an interactive shell to execute commands on the compromised system.
Description
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php.
Exploits (2)
This exploit targets a remote command execution vulnerability in FlexPaper PHP Publish Service <= 2.3.6. It deletes the target configuration file, uploads a webshell, and provides an interactive shell to execute commands on the compromised system.
This PoC exploits CVE-2018-11686, an authentication bypass and command injection vulnerability in FlexPaper PHP Publish Service <= 2.3.6. It leverages unauthenticated access to delete config files and inject commands via the setup process.
Nuclei Templates (1)
title:"FlexPaper"
title="FlexPaper"
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H