github.com
https://github.com/Athlon1600/php-proxy-app/issues/134 CVE-2018-19246
HIGH
LFI in PHP-Proxy 5.1.0
Record summary
CVE-2018-19246 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users who lack shell access to their web server) is used. This occurs because the aeb067ca0aa9a3193dce3a7264c90187 app_key value from the default config.php is in place, and this value can be easily used to calculate the authorization data needed for local file inclusion.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
athlon1600/php-proxyBrowse Packagist / athlon1600/php-proxy | GitHub Advisory | Through 5.1.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBPHP-Proxy 5.1.0 - Local File InclusionExploitDB exploitby Ameer PornillosNot analyzed1 file
References
4github.com
https://github.com/Athlon1600/php-proxy/pull/126 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-19246 45861exploit
https://www.exploit-db.com/exploits/45861