Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-18951. PoCs published by Noman Riffat.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in Xfilesharing <=2.5.1, allowing attackers to upload malicious files via a crafted form submission. It also includes a local file inclusion (LFI) technique to fetch sensitive files or achieve remote code execution (RCE) by leveraging built-in shortcodes.
Description
SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files.
Exploits (1)
This exploit demonstrates an arbitrary file upload vulnerability in Xfilesharing <=2.5.1, allowing attackers to upload malicious files via a crafted form submission. It also includes a local file inclusion (LFI) technique to fetch sensitive files or achieve remote code execution (RCE) by leveraging built-in shortcodes.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N