CVE-2018-9206 is an unauthenticated unrestricted file upload vulnerability affecting Blueimp jQuery-File-Upload versions up to and including 9.22.0. The flaw allows a remote attacker to submit arbitrary files to exposed upload handlers without authentication. In deployments where uploaded server-side script content is accepted and stored in a web-accessible location, the vulnerability can be leveraged to execute attacker-controlled code on the server. The issue is commonly characterized as an arbitrary file upload leading to remote code execution, depending on server configuration and how the application handles uploaded content.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository provides a vulnerable Docker environment for demonstrating and exploiting CVE-2018-9206, an unrestricted file upload vulnerability in Blueimp jQuery-File-Upload <= 9.22.0. The structure includes a Dockerfile and docker-compose.yml for easy setup, a web application (HTML/JS frontend), the vulnerable PHP backend (UploadHandler.php and index.php), and a Bash proof-of-concept script (scripts/poc.sh) that automates the exploit. The exploit works by uploading a PHP file via the vulnerable endpoint (/jQuery-File-Upload/server/php/index.php), which is then stored in a web-accessible directory (/jQuery-File-Upload/server/php/files/). The uploaded PHP file can be executed remotely, confirming remote code execution. The PoC script demonstrates this by uploading a PHP file that echoes a unique marker and then accessing it to verify execution. The repository targets Blueimp jQuery-File-Upload <= 9.22.0, specifically when deployed with Apache configured to disallow .htaccess overrides (AllowOverride None), which is the default in the provided Docker setup. The main attack vector is network-based, exploiting the file upload endpoint over HTTP. The repository is operational, providing a working exploit and environment for testing and demonstration.
This repository contains a single Metasploit module (modules/exploits/unix/webapp/jquery_file_upload.rb) that exploits an arbitrary file upload vulnerability in blueimp's jQuery File Upload widget (CVE-2018-9206) for versions <= 9.22.0. The exploit targets web servers (typically Apache >= 2.3.9) where the .htaccess file is ignored, allowing attackers to upload and execute arbitrary PHP code. The module automatically detects the presence of the vulnerable upload handler by probing several common endpoints, uploads a PHP payload, executes it, and then attempts to delete the payload. The exploit is fully weaponized, leveraging Metasploit's payload generation and delivery mechanisms, and provides remote code execution on the target server. The only file in the repository is the Metasploit exploit module written in Ruby.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0, allowing attackers to upload and execute malicious files on the server.
An unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload that allows attackers to upload files to the server without authentication, potentially leading to remote code execution.
A critical unrestricted file upload vulnerability in Blueimp jQuery-File-Upload, allowing attackers to upload arbitrary files and potentially achieve remote code execution.
A critical arbitrary file upload vulnerability in the blueimp jQuery-File-Upload plugin, allowing remote attackers to execute arbitrary PHP code on the server.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.