Back
CVE-2018-19127
CRITICAL
A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a controllable filename, leading to arbitrary code execution. The PHP code is sent via the template parameter, and is written to a data/cache_template/*.tpl.php file along with a "<?php function " substring.
Published: Nov 9, 2018
Modified: Jun 17, 2026
CWE-94
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| phpcms | phpcms | 2008 |
GitHub Security Advisory GHSA-p498-q357-m3p7
A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary...
References (2)
- https://github.com/ab1gale/phpcms-2008-CVE-2018-19127 Third Party Advisory
- https://github.com/ab1gale/phpcms-2008-CVE-2018-19127 Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
20.77%
Top 3% most likely to be exploited
Threat Score
45.4 / 100
Data Sources
NVD
EPSS
GitHub