metalamin.github.io
https://metalamin.github.io/MachForm-not-0-day-EN CVE-2018-6411
CRITICAL
MachForm < 4.2.3 - SQL Injection / Path Traversal / Upload Bypass
Record summary
CVE-2018-6411 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to the filters. If the filter is set to a whitelist, the dangerous extensions can be bypassed through ap_form_elements SQL Injection.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMachForm < 4.2.3 - SQL Injection / Path Traversal / Upload BypassExploitDB exploitby Amine TaouirsaNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-6411 44804exploit
https://www.exploit-db.com/exploits/44804 machform.com
https://www.machform.com/blog-machform-423-security-release