Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-19404

In YXcms 1.4.7, protected/apps/appmanage/controller/indexController.php allow remote authenticated Administrators to execute any PHP code by creating a ZIP archive containing a config.php file, hosting the .zip file at an external URL, and visiting index.php?r=appmanage/index/onlineinstall&url= followed by that URL. This is related to the onlineinstall and import functions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 75.1%
CVSS Severity
CVSS v3 Score 7.2
CVSS v2 Score 6.5
Products affected by CVE-2018-19404
  • Yxcms » Yxcms » Version: 1.4.7
    cpe:2.3:a:yxcms:yxcms:1.4.7


Contact Us

Shodan ® - All rights reserved