Vulnerabilities > CVE-2018-19125 - Unspecified vulnerability in Prestashop

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
prestashop
exploit available

Summary

PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to delete an image directory.

Vulnerable Configurations

Part Description Count
Application
Prestashop
79

Exploit-Db

fileexploits/php/webapps/45964.php
idEDB-ID:45964
last seen2018-12-11
modified2018-12-11
platformphp
port80
published2018-12-11
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/45964
titlePrestaShop 1.6.x/1.7.x - Remote Code Execution
typewebapps

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/150757/prestashop1617-exec.txt
idPACKETSTORM:150757
last seen2018-12-12
published2018-12-12
reporterfarisv
sourcehttps://packetstormsecurity.com/files/150757/PrestaShop-1.6.x-1.7.x-Remote-Code-Execution.html
titlePrestaShop 1.6.x / 1.7.x Remote Code Execution