CVE-2019-9194 is a command injection vulnerability affecting elFinder before version 2.1.48. The issue is in the PHP connector component and allows an attacker to inject and execute arbitrary OS commands on the underlying server. The provided content specifically identifies elFinder 2.1.47 as vulnerable and notes successful remote code execution via exploitation of this flaw.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a single Python exploit script (CVE-2019-9194.py) and a README describing usage and prerequisites. The exploit targets CVE-2019-9194 in elFinder <= 2.1.47, abusing command injection in the PHP connector’s image rotation/resize functionality (exiftran invocation) by uploading a valid JPEG whose *filename* includes shell metacharacters and commands. Operational flow: 1) upload(): Sends a multipart POST to /php/connector.minimal.php with cmd=upload and an upload[] file whose filename is crafted as: "SecSignal.jpg; echo <hex> | xxd -r -p > SecSignal.php; echo SecSignal.jpg". This injects a command that writes a PHP webshell (SecSignal.php) into the server’s /php/ directory. 2) img_rotate(): Sends a GET to /php/connector.minimal.php with cmd=resize&mode=rotate and target=<uploaded file hash> to trigger the vulnerable image processing path that executes the injected filename. 3) shell(): Checks /php/SecSignal.php; if present, enters an interactive loop that issues commands by requesting /php/SecSignal.php?c=<cmd> and prints the response. Key capabilities: unauthenticated remote code execution, persistent webshell drop, and interactive command execution over HTTP. No scanning/detection-only behavior; it is a direct exploitation PoC with a hardcoded webshell payload.
This repository contains a single Metasploit module targeting a command injection vulnerability (CVE-2019-9194) in the elFinder PHP Connector (versions prior to 2.1.48). The exploit leverages improper sanitization of uploaded file names, which are passed unsafely to the 'exiftran' utility, allowing arbitrary shell command execution. The module works by uploading a specially crafted JPEG file (containing a PHP payload) with a malicious filename, then triggering the vulnerable image rotation functionality to execute the payload. The exploit is fully weaponized, supporting customizable Metasploit payloads for remote code execution. The main fingerprintable endpoint is the PHP connector script, typically located at '/elFinder/php/connector.minimal.php'. The exploit requires the PHP connector to be enabled and the 'exiftran' utility to be present on the target system. The repository is structured as a single Ruby file within the Metasploit framework, implementing all necessary logic for exploitation, payload delivery, and cleanup.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.