CVE-2019-12744
HIGHseeddms < 5.1.11 - Remote Command Execution via Unvalidated PHP File Upload
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2019-12744. PoCs published by Bryan Leong, Nimit Jain, nobodyatall648.
AI-analyzed exploit summary This exploit demonstrates an authenticated RCE vulnerability in Seeddms 5.1.10 by uploading a malicious PHP file and executing system commands. It follows a multi-step process involving login, token capture, file upload, and shell spawning.
Description
SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a different vulnerability than CVE-2018-12940.
Exploits (3)
This exploit demonstrates an authenticated RCE vulnerability in Seeddms 5.1.10 by uploading a malicious PHP file and executing system commands. It follows a multi-step process involving login, token capture, file upload, and shell spawning.
This exploit demonstrates a remote command execution vulnerability in SeedDMS versions <5.1.11 due to unvalidated file upload. Attackers can upload a malicious PHP file and execute arbitrary commands via a crafted request.
This repository contains a functional Python exploit for CVE-2019-12744, which targets an unvalidated file upload vulnerability in SeedDMS versions < 5.1.11. The exploit authenticates, uploads a malicious PHP file, and executes arbitrary commands via a reverse shell.
References (4)
Scores
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H