Vulnerability Description
Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=metadata§ion=cpanel&page=list_filetypes request.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Afian | Filerun | <= 2017.09.25 |
Related Weaknesses (CWE)
References
- http://www.filerun.com/changelogVendor Advisory
- https://feedback.filerun.com/communities/1/topics/189-critical-security-update-aVendor Advisory
- https://www.scanfsec.com/FileRun_2017_09_25_Blind_SQL.htmlExploitThird Party Advisory
- http://www.filerun.com/changelogVendor Advisory
- https://feedback.filerun.com/communities/1/topics/189-critical-security-update-aVendor Advisory
- https://www.scanfsec.com/FileRun_2017_09_25_Blind_SQL.htmlExploitThird Party Advisory
FAQ
What is CVE-2018-7735?
CVE-2018-7735 is a vulnerability with a CVSS score of 7.2 (HIGH). Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=metadata§ion=cpanel&page=list_filetypes req...
How severe is CVE-2018-7735?
CVE-2018-7735 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-7735?
Check the references section above for vendor advisories and patch information. Affected products include: Afian Filerun.