CVE-2018-18982
CVE-2018-18982
Vexday Risk Score
50Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS —EPSS 60.8%KEV nãoPoC públicaNuclei —Metasploit simPatch —
Lifecycle
11 Oct 2018Metasploit module available
27 Nov 2018Published on NVD
22 Feb 2019Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an executing statement and allow arbitrary code execution.
Affected products
n/a · NUUO CMSpublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/46449/unverifiedexploitdbwww.exploit-db.com/exploits/46449unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →