CVE-2023-38836 is a file upload vulnerability in BoidCMS version 2.0.0. The vulnerability allows authenticated attackers to upload files with dangerous types, such as PHP scripts, by bypassing MIME type checks. This is achieved by prepending a GIF header to the PHP payload, which tricks the server into accepting the file as a safe image type. Once uploaded, the attacker can execute arbitrary code on the server, leading to remote code execution (RCE).
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module (modules/exploits/multi/http/cve_2023_38836_boidcms.rb) that exploits CVE-2023-38836, a command injection vulnerability in BoidCMS version 2.0.0 and below. The exploit works by authenticating to the BoidCMS admin interface, uploading a PHP webshell disguised as a GIF image via the media upload functionality, and then triggering the webshell to execute arbitrary OS commands. The module supports both Linux/Unix and Windows targets, with default payloads for each platform (meterpreter reverse shell). The exploit requires valid admin credentials and network access to the BoidCMS admin interface. The main endpoints involved are the /admin login page and the /media/ directory where the malicious PHP file is uploaded and executed. The code is written in Ruby and is fully integrated into the Metasploit framework, making it weaponized and easy to use for attackers.
This repository contains a Python exploit script (CVE-2023-38836.py) targeting an authenticated file upload vulnerability in BoidCMS versions 2.0.0 and below (CVE-2023-38836). The exploit requires valid admin credentials for the target BoidCMS instance. It works by logging into the admin panel, navigating to the media upload page, and uploading a PHP reverse shell disguised with a GIF header to bypass file type checks. Once uploaded, the shell is accessible at /media/shell.php on the target server. The attacker must set up a listener on their own machine to receive the reverse shell connection. The repository also includes a README with usage instructions and a LICENSE file. The main exploit file is written in Python and generates a PHP payload for remote code execution. The attack vector is network-based, requiring access to the BoidCMS admin interface.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.