dev.cmsmadesimple.org
http://dev.cmsmadesimple.org/project/changelog/5471 CVE-2018-7448
HIGH
CMS Made Simple 2.1.6 - Remote Code Execution
Record summary
CVE-2018-7448 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" parameter in step 4 of a fresh installation procedure.
Description source: CVE List
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBCMS Made Simple 2.1.6 - Remote Code ExecutionExploitDB exploitby Keerati T.Not analyzed1 file
Repository PoCs
GitHubb1d0ws/exploit-cve-2018-7448Repository PoCby b1d0wsStars: 1Not analyzed2 files
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-7448 packetstormsecurity.com
https://packetstormsecurity.com/files/146568/CMS-Made-Simple-2.1.6-Remote-Code-Execution.html 44192exploit
https://www.exploit-db.com/exploits/44192