Arbitrary file upload in jQuery File Upload - CVE-2018-9206
Published: October 19, 2018 / Updated: June 17, 2021
Vulnerability identifier: #VU15424
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-9206
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
Note: The vulnerability has been actively exploited for at least 3 years.
The vulnerability exists in the plugin's source code that handles file uploads to PHP servers due to software allows upload of arbitrary files to the system. A remote unauthenticated attacker can upload arbitrary .htaccess file to impose security restrictions to its upload folder and upload backdoors and web shells.
Note: The vulnerability has been actively exploited for at least 3 years.
Affected software
jQuery File Upload
Nessus Network Monitor
Primavera Unifier
Oracle Communications Services Gatekeeper
Siebel UI Framework
Nessus Network Monitor
Primavera Unifier
Oracle Communications Services Gatekeeper
Siebel UI Framework
How to mitigate CVE-2018-9206
Update to version 9.22.1 or later.
jQuery File Upload - addressed in versions 9.22.1, 9.22.2, 9.23.0
Nessus Network Monitor - update to 6.3.1
Oracle Communications Services Gatekeeper - update to 6.1.0.4.0
Nessus Network Monitor - update to 6.3.1
Oracle Communications Services Gatekeeper - update to 6.1.0.4.0
Links to Public Exploits and PoC-codes
- Exploit #6048 - blueimp's jQuery 9.22.0 - (Arbitrary) File Upload (Metasploit) (June 17, 2021)
- Exploit #5962 - Blueimp's jQuery File Upload 9.22.0 - Arbitrary File Upload Exploit (June 17, 2021)
- Exploit #5986 - jQuery-File-Upload 9.22.0 - Arbitrary File Upload (June 17, 2021)
- Exploit #215 - Exploits (Exploits for various CVEs) (March 18, 2020)
- Exploit #1533 - blueimp's jQuery (Arbitrary) File Upload (March 18, 2020)
External References
Related Security Bulletins
- Arbitrary file upload in jQuery File Upload plugin
- Multiple vulnerabilities in Oracle Primavera
- Arbitrary file upload in Oracle Siebel UI Framework
- Arbitrary file upload in blueimp jQuery File Upload
- Tenable Nessus Network Monitor update for third-party components
- Arbitrary file upload in Siebel UI Framework
- Multiple vulnerabilities in Primavera Unifier
- Multiple vulnerabilities in Oracle Communications Services Gatekeeper