CVE-2018-19246
Last modified
CVE-2018-19246 is a vulnerability of currently unknown severity. PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users who lack shell access to their web server) is used. This occurs because the aeb067ca0aa9a3193dce3a7264c90187 app_key value from the default config.php is in place, and this value can be easily used to calculate the authorization data needed for local file inclusion.. EPSS estimates a 22.52% chance of exploitation in the next 30 days.
Description
PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users who lack shell access to their web server) is used. This occurs because the aeb067ca0aa9a3193dce3a7264c90187 app_key value from the default config.php is in place, and this value can be easily used to calculate the authorization data needed for local file inclusion.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Php-Proxy | Php-Proxy | 5.1.0 |
References
- https://github.com/Athlon1600/php-proxy-app/issues/134Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/45861/Exploit, Third Party Advisory, VDB Entry
- https://github.com/Athlon1600/php-proxy-app/issues/134Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/45861/Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-19246?
How severe is CVE-2018-19246?
How do I fix CVE-2018-19246?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-19234The Miss Marple Updater Service in COMPAREX Miss Marple Ente…
- CVE-2018-19239TRENDnet TEW-673GRU v1.00b40 devices have an OS command inje…
- CVE-2018-19240Buffer overflow in network.cgi on TRENDnet TV-IP110WN V1.2.2…
- CVE-2018-19241Buffer overflow in video.cgi on TRENDnet TV-IP110WN V1.2.2 b…
- CVE-2018-19242Buffer overflow in apply.cgi on TRENDnet TEW-632BRP 1.010B32…
- CVE-2018-19244An XML External Entity (XXE) vulnerability exists in the Cha…
- CVE-2018-19248The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Reco…
- CVE-2018-19249The Stripe API v1 allows remote attackers to bypass intended…
- CVE-2018-1925IBM WebShere MQ 9.1.0.0, 9.1.0.1, 9.1.1 uses weaker than exp…5.9
- CVE-2018-19250Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2018-19251Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2018-19252Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
Are you affected by CVE-2018-19246?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
