CVE-2019-18952
CRITICAL EXPLOITED IN THE WILD NUCLEISibSoft Xfilesharing <2.5.1 - Code Injection
Title source: llmDescription
SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execution via a .html file, containing short codes, that is served over HTTP.
Nuclei Templates (1)
Xfilesharing 2.5.1 - Arbitrary File Upload
CRITICALby daffainfo
Shodan:
html:"/?op=registration" "OpenSSL"
Scores
CVSS v3
9.8
EPSS
0.8469
EPSS Percentile
99.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2022-01-12
InTheWild.io
2021-11-11
CWE
CWE-434
Status
published
Products (1)
sibsoft/xfilesharing
< 2.5.1
Published
Nov 13, 2019
Tracked Since
Feb 18, 2026