Bludit 3.9.2 contains an improper restriction of authentication attempts in bl-kernel/security.class.php. An attacker can evade its brute-force protection mechanism by repeatedly submitting requests with different forged X-Forwarded-For or Client-IP HTTP header values, causing the protection to treat attempts as originating from different clients.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a small standalone Python exploit project consisting of a license, a descriptive README, and a single executable script, poc.py. The script is the sole operational component and serves as the entry point. It automates a chained attack against Bludit CMS by combining CVE-2019-17240 and CVE-2019-16113. Operationally, the exploit accepts a target base URL, an admin username, an attacker listener IP, and either a single password or a password file. It constructs three main target URLs: /admin/login for CSRF retrieval and credential brute forcing, /admin/new-content for obtaining an authenticated CSRF token prior to upload, and /admin/ajax/upload-images for file upload. During brute force, it creates a fresh requests session per password attempt and varies the X-Forwarded-For header with the loop counter to evade rate limiting. Success is inferred from a redirect to /admin/dashboard. Once a valid password is found, the script logs in using a shared global session, preserving authentication state for subsequent requests. It then generates a random 10-character PHP filename, builds a PHP payload that executes /bin/bash to connect back to the attacker over /dev/tcp/{listener_ip}/{listener_port}, and uploads both that PHP file and a .htaccess file. Finally, it triggers the uploaded shell by issuing an HTTP GET to /bl-content/tmp/{payload_name}.php. The trigger logic treats timeouts or connection errors as potentially successful shell execution, which is consistent with reverse-shell behavior. The repository is clearly an exploit rather than a detector: it performs credential attacks, authenticated upload, and payload execution. It is not part of a larger exploitation framework. The code is functional but simple, with minimal error handling and no advanced payload customization beyond listener IP/port and password source, making it best categorized as OPERATIONAL rather than weaponized.
This repository contains a Python proof-of-concept exploit (poc.py) targeting Bludit CMS versions 3.9.2 and below, leveraging two vulnerabilities: CVE-2019-17240 (authentication bypass via X-Forwarded-For header manipulation) and CVE-2019-16113 (arbitrary file upload). The exploit automates the process of brute-forcing admin credentials, bypassing rate limits, uploading a PHP reverse shell and a .htaccess file to ensure code execution, and then triggering the shell to connect back to an attacker's listener. The main code file is poc.py, which is a standalone script requiring Python 3.6+ and the requests library. The README.md provides detailed usage instructions, requirements, and background on the vulnerabilities. The exploit is operational, providing a working reverse shell payload, and is not part of a larger framework. The endpoints targeted are typical of Bludit's admin interface and file upload mechanisms. No hardcoded IPs or domains are present; the script is parameterized for attacker and target details.
This repository contains a Python exploit script (script.py) targeting CVE-2019-17240, a vulnerability in Bludit 3.9.2 that allows authentication brute-force bypass. The script automates login attempts against the Bludit admin interface, bypassing IP-based brute-force protections by randomizing the X-Forwarded-For HTTP header for each request. It supports multi-threaded operation and can take username and password lists as input, either as direct values or file paths. The script is a proof-of-concept exploit and does not provide a post-exploitation payload; its main capability is to discover valid admin credentials. The repository also includes a README.md (briefly describing the exploit), a LICENSE (GPLv3), and a .gitignore. The main entry point is script.py, which is self-contained and does not rely on external frameworks.
This repository contains a Bash script (CVE-2019-17240) and a README.md. The script is an exploit for CVE-2019-17240, targeting Bludit CMS versions <= 3.9.2. It automates brute-force attacks against the login page by bypassing CSRF token-based protections. The script takes as input a login URL, a username, and a password file, then iteratively attempts logins by dynamically extracting CSRF tokens and submitting them with each password. Successful login is detected by observing a redirect to the admin dashboard. The script provides a progress bar for usability and stores session cookies in a local file (cookies.txt). The README.md provides detailed usage instructions, background on the vulnerability, and credits. The exploit is a proof-of-concept and does not include post-exploitation payloads; its main capability is credential brute-forcing via a network attack vector.
This repository contains a Python exploit script (bludit.py) targeting Bludit CMS, specifically exploiting CVE-2019-17240. The exploit bypasses login mitigations, logs in as an admin user (using hardcoded credentials), and uploads a malicious PHP payload and a .htaccess file to the server. The PHP payload, when accessed, initiates a reverse shell connection to the attacker's machine (10.10.14.30:9001). The script automates the process of obtaining CSRF tokens, logging in, uploading the payload, and triggering the shell. The repository also includes a brief README describing its purpose. The main attack vector is network-based, targeting the web interface of Bludit CMS. Several HTTP endpoints are fingerprintable, as well as the attacker's IP address for the reverse shell connection. The exploit is operational, providing a working payload and automation for exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.