CVE-2018-25412

Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted multipart form data. Attackers can upload PHP files with arbitrary content to the upload directory and execute them on the server for remote code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:deltasql_project:deltasql:1.8.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-30 16:17

Updated : 2026-07-22 06:10


NVD link : CVE-2018-25412

Mitre link : CVE-2018-25412

CVE.ORG link : CVE-2018-25412


JSON object : View

Products Affected

deltasql_project

  • deltasql
CWE
CWE-306

Missing Authentication for Critical Function