Bludit 3.9.2 suffers from a remote code execution vulnerability in the file upload functionality of /bl-kernel/admin/ajax/upload-images.php. Authenticated users with content editing permissions can upload files with crafted extensions (e.g., .jpg containing PHP code), which are not properly validated. The vulnerable code allows these files to be written to arbitrary locations, including parent directories, enabling attackers to upload and execute arbitrary PHP code on the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
7 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a small standalone Python exploit project consisting of a license, a descriptive README, and a single executable script, poc.py. The script is the sole operational component and serves as the entry point. It automates a chained attack against Bludit CMS by combining CVE-2019-17240 and CVE-2019-16113. Operationally, the exploit accepts a target base URL, an admin username, an attacker listener IP, and either a single password or a password file. It constructs three main target URLs: /admin/login for CSRF retrieval and credential brute forcing, /admin/new-content for obtaining an authenticated CSRF token prior to upload, and /admin/ajax/upload-images for file upload. During brute force, it creates a fresh requests session per password attempt and varies the X-Forwarded-For header with the loop counter to evade rate limiting. Success is inferred from a redirect to /admin/dashboard. Once a valid password is found, the script logs in using a shared global session, preserving authentication state for subsequent requests. It then generates a random 10-character PHP filename, builds a PHP payload that executes /bin/bash to connect back to the attacker over /dev/tcp/{listener_ip}/{listener_port}, and uploads both that PHP file and a .htaccess file. Finally, it triggers the uploaded shell by issuing an HTTP GET to /bl-content/tmp/{payload_name}.php. The trigger logic treats timeouts or connection errors as potentially successful shell execution, which is consistent with reverse-shell behavior. The repository is clearly an exploit rather than a detector: it performs credential attacks, authenticated upload, and payload execution. It is not part of a larger exploitation framework. The code is functional but simple, with minimal error handling and no advanced payload customization beyond listener IP/port and password source, making it best categorized as OPERATIONAL rather than weaponized.
This repository contains a Python proof-of-concept exploit (poc.py) targeting Bludit CMS versions 3.9.2 and below, leveraging two vulnerabilities: CVE-2019-17240 (authentication bypass via X-Forwarded-For header manipulation) and CVE-2019-16113 (arbitrary file upload). The exploit automates the process of brute-forcing admin credentials, bypassing rate limits, uploading a PHP reverse shell and a .htaccess file to ensure code execution, and then triggering the shell to connect back to an attacker's listener. The main code file is poc.py, which is a standalone script requiring Python 3.6+ and the requests library. The README.md provides detailed usage instructions, requirements, and background on the vulnerabilities. The exploit is operational, providing a working reverse shell payload, and is not part of a larger framework. The endpoints targeted are typical of Bludit's admin interface and file upload mechanisms. No hardcoded IPs or domains are present; the script is parameterized for attacker and target details.
This repository contains a Python exploit script (script.py) targeting CVE-2019-16113, a remote command execution vulnerability in Bludit CMS version 3.9.2. The exploit works by authenticating to the Bludit admin panel using provided credentials, uploading a malicious PHP payload disguised as a JPG image, and a .htaccess file that enables PHP execution for .jpg files. The script then triggers the payload by accessing the uploaded file, allowing arbitrary command execution on the server. The exploit requires network access to the target, valid admin credentials, and the Bludit instance to be accessible. The repository is structured with a single exploit script, a README, a license, and a .gitignore file. The main entry point is script.py, which is a standalone Python script. No hardcoded IPs or domains are present; all target information is supplied via command-line arguments.
This repository contains a single Metasploit module targeting Bludit CMS (v3.9.2) for a directory traversal and file upload vulnerability (CVE-2019-16113). The exploit abuses the image upload feature by manipulating the 'uuid' parameter to traverse directories and upload a PHP payload disguised as a .png file. A custom .htaccess file is also uploaded to bypass file extension checks, allowing the payload to be executed as PHP. The module requires valid Bludit credentials and interacts with several HTTP endpoints, including the login and image upload routes. Upon successful exploitation, the attacker gains remote code execution on the target server. The code is written in Ruby and leverages Metasploit's framework for HTTP requests, payload generation, and session management.
This repository contains a Python proof-of-concept exploit for CVE-2019-16113, a remote code execution vulnerability in Bludit CMS version 3.9.2 and above. The exploit works by logging into the Bludit admin panel (using provided or default credentials), extracting a CSRF token, and abusing the image upload functionality to upload a PHP webshell disguised as a PNG file. It also uploads a .htaccess file to ensure the webserver executes the PNG as PHP. Finally, it accesses the uploaded file to trigger execution of an arbitrary command, which by default is a reverse shell to the attacker's machine. The repository consists of the main exploit script (CVE-2019-16113.py) and a README.md with usage instructions. The exploit requires Python 3 and the 'requests' library. The main attack vector is network-based, targeting the Bludit admin interface and upload endpoint.
This repository contains a Python proof-of-concept exploit for CVE-2019-16113, a directory traversal and file upload vulnerability in Bludit 3.9.2. The exploit consists of a single Python script (cve-2019-16113.py) and a README.md file. The script automates the process of authenticating to the Bludit admin panel, uploading a PHP reverse shell disguised as a .png file via a vulnerable image upload endpoint, and modifying the .htaccess file to allow execution of PHP code in .png files. Once the payload is uploaded, the script triggers the payload by accessing the uploaded file, resulting in a reverse shell connection to the attacker's machine. The exploit requires valid Bludit admin credentials and network access to the target. The main endpoints targeted are the Bludit admin login, image upload, and the directory where uploaded files are stored. The payload is a PHP reverse shell, and the attack vector is remote network exploitation via HTTP.
This repository contains a Python exploit script (CVE-2019-16113.py) targeting Bludit CMS versions >= 3.9.12, exploiting an authenticated directory traversal vulnerability in the image upload functionality (CVE-2019-16113). The exploit requires valid admin credentials and works by logging in, obtaining CSRF tokens, and uploading a PHP webshell disguised as a .jpg file to a writable directory using directory traversal in the 'uuid' parameter. It also uploads a .htaccess file to ensure the webshell is executed as PHP. The script then triggers the webshell by accessing its URL, executing an arbitrary command provided by the attacker. The README.md provides usage instructions and an example reverse shell payload. The main attack vector is network-based, requiring HTTP(S) access to the Bludit admin panel. The endpoints involved are the admin login, image upload, and the webshell's final location. The exploit is operational, providing a working RCE payload, but requires attacker-supplied credentials.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.