metalamin.github.io
https://metalamin.github.io/MachForm-not-0-day-EN CVE-2018-6410
CRITICAL
MachForm < 4.2.3 - SQL Injection / Path Traversal / Upload Bypass
Record summary
CVE-2018-6410 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMachForm < 4.2.3 - SQL Injection / Path Traversal / Upload BypassExploitDB exploitby Amine TaouirsaNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-6410 44804exploit
https://www.exploit-db.com/exploits/44804 machform.com
https://www.machform.com/blog-machform-423-security-release