CVE-2018-17418
HIGHMonstra CMS 3.0.4 - Remote Code Execution via Mixed-Case File Extension Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-17418. PoCs published by Jx0n0.
AI-analyzed exploit summary This PoC demonstrates a file upload vulnerability in Monstra CMS 3.0.4 (CVE-2018-17418) by bypassing blacklist restrictions via case manipulation (e.g., 'PhP' instead of 'php'). The exploit allows arbitrary file upload leading to remote code execution (RCE).
Description
Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filename, because plugins\box\filesmanager\filesmanager.admin.php mishandles the forbidden_types variable.
Exploits (1)
This PoC demonstrates a file upload vulnerability in Monstra CMS 3.0.4 (CVE-2018-17418) by bypassing blacklist restrictions via case manipulation (e.g., 'PhP' instead of 'php'). The exploit allows arbitrary file upload leading to remote code execution (RCE).
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H