Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-19514

In Webgalamb through 7.0, an arbitrary code execution vulnerability could be exploited remotely without authentication. Exploitation requires authentication bypass to access administrative functions of the site to upload a crafted CSV file with a malicious payload that becomes part of a PHP eval() expression in the subscriber.php file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.053
EPSS Ranking 89.6%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2018-19514
  • Ens » Webgalamb » Version: 6.0
    cpe:2.3:a:ens:webgalamb:6.0
  • Ens » Webgalamb » Version: 7.0
    cpe:2.3:a:ens:webgalamb:7.0


Contact Us

Shodan ® - All rights reserved