Skip to content

Commit

Permalink
change the cve name CVE-2018-19158 in CVE-2018-19518 (vulhub#92)
Browse files Browse the repository at this point in the history
  • Loading branch information
EmilienMottet authored and phith0n committed Dec 30, 2018
1 parent 34bb706 commit 3ac5dce
Show file tree
Hide file tree
Showing 4 changed files with 3 additions and 2 deletions.
File renamed without changes
5 changes: 3 additions & 2 deletions php/CVE-2018-19158/README.md → php/CVE-2018-19518/README.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# PHP imap 远程命令执行漏洞(CVE-2018-19158
# PHP imap 远程命令执行漏洞(CVE-2018-19518

php imap扩展用于在PHP中执行邮件收发操作。其`imap_open`函数会调用rsh来连接远程shell,而debian/ubuntu中默认使用ssh来代替rsh的功能(也就是说,在debian系列系统中,执行rsh命令实际执行的是ssh命令)。

Expand All @@ -9,6 +9,7 @@ php imap扩展用于在PHP中执行邮件收发操作。其`imap_open`函数会
- https://bugs.php.net/bug.php?id=77153
- https://github.com/Bo0oM/PHP_imap_open_exploit
- https://antichat.com/threads/463395/#post-4254681
- https://nvd.nist.gov/vuln/detail/CVE-2018-19518

## 漏洞环境

Expand Down Expand Up @@ -42,4 +43,4 @@ hostname=x+-oProxyCommand%3decho%09ZWNobyAnMTIzNDU2Nzg5MCc%2bL3RtcC90ZXN0MDAwMQo

执行`docker-compose exec web bash`进入容器,可见`/tmp/test0001`已成功创建:

![](1.png)
![](1.png)
File renamed without changes.
File renamed without changes.

0 comments on commit 3ac5dce

Please sign in to comment.