Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-58313

xbtitFM 4.1.18 contains an insecure file upload vulnerability that allows authenticated attackers with administrative privileges to upload and execute arbitrary PHP code through the file_hosting feature. Attackers can bypass file type restrictions by modifying the Content-Type header to image/gif, adding GIF89a magic bytes, and using alternate PHP tags to upload web shells that execute system commands.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 15.0%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2024-58313
  • Xbtitfm » Xbtitfm » Version: 4.1.18
    cpe:2.3:a:xbtitfm:xbtitfm:4.1.18


Contact Us

Shodan ® - All rights reserved