In Subrion CMS 4.2.1, the /panel/uploads endpoint allows authenticated admin users to upload files with .pht and .phar extensions. Due to an incomplete .htaccess configuration in the uploads directory, these file types are not blacklisted, enabling them to be executed as PHP scripts on certain server environments. This oversight allows for remote code execution if an attacker obtains admin credentials and uploads a malicious file.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Python exploit script (CVE-2018-19422.py) and a README for CVE-2018-19422, targeting SubrionCMS version 4.2.1. The exploit leverages an authenticated file upload bypass to achieve remote code execution (RCE). The script automates the process of logging into the SubrionCMS admin panel, uploading a PHP webshell (disguised as a .phar file to bypass .htaccess restrictions), and then provides an interactive shell for executing commands on the target server. The exploit requires valid credentials and the BeautifulSoup library. The README provides usage instructions and example output. The main endpoints targeted are the admin login page, the file upload handler, and the uploads directory where the webshell is accessed. The payload is a simple PHP webshell that executes commands passed via the 'cmd' GET parameter. The repository is operational and provides a working exploit for authenticated attackers.
This repository contains a single Metasploit module (Ruby file) that exploits an authenticated file upload vulnerability (CVE-2018-19422) in Intelliants Subrion CMS versions 4.2.1 and below. The exploit leverages the fact that the .htaccess file does not block execution of .phar, .pht, or .xhtml files, allowing an attacker with valid admin credentials to upload a malicious PHP payload (by default, a Meterpreter reverse shell) as a .phar file. The module authenticates to the admin panel, uploads the payload via the /panel/uploads/read.json endpoint, and then executes it by accessing the uploaded file in the /uploads/ directory. The payload is configured to self-delete after execution. The exploit is weaponized, as it is part of the Metasploit framework and supports customizable payloads. The only file in the repository is the Metasploit module itself, written in Ruby.
This repository contains a Python exploit script (SubrionRCE.py) targeting SubrionCMS version 4.2.1, specifically exploiting CVE-2018-19422. The exploit leverages an authenticated file upload vulnerability in the /panel/uploads endpoint, which allows uploading of .phar or .pht files due to improper .htaccess restrictions. The script logs into the SubrionCMS admin panel using provided credentials, uploads a PHP webshell, and then provides an interactive shell to execute arbitrary system commands on the target server. The payload is a simple PHP webshell. The repository also includes a README with usage instructions and references, and a placeholder image file. The main attack vector is network-based, requiring access to the web admin panel. The endpoints involved are the login page, the file upload handler, and the uploads directory where the shell is accessed.
This repository contains a Python exploit script (exploit.py) and a README.md. The exploit targets SubrionCMS version 4.2.1 (CVE-2018-19422) and leverages an authenticated file upload vulnerability to achieve remote code execution (RCE). The script requires valid credentials for the CMS and uses BeautifulSoup to parse CSRF tokens from the login page. After authenticating, it uploads a randomly named PHP webshell to the server via a crafted multipart/form-data POST request. The webshell allows the attacker to execute arbitrary system commands by passing them as the 'cmd' parameter in HTTP requests. The README documents a usability fix related to URL formatting. The exploit is operational, providing a working webshell if the target is vulnerable and credentials are known. The main endpoints involved are the login page, the file upload handler, and the uploads directory where the shell is placed.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.