Vulnerability detail
Enriched intelligence for a single CVE
Critical
CVE-2018-16763
PUBLISHEDFUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote...
- Vendor
- Daylight Studio
- Product
- FUEL CMS
- Published
- Sep 09, 2018
- EPSS
- —
Description
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.
CVSS scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitation status
Proof of concept available
Recorded 2022-05-31 15:31:37 UTC · Source
References
- https://github.com/daylightstudio/FUEL-CMS/issues/478
- https://0xd0ff9.wordpress.com/2019/07/19/from-code-evaluation-to-pre-auth-remote-code-execution-cve-2018-16763-bypass/
- https://www.exploit-db.com/exploits/47138
- http://packetstormsecurity.com/files/153696/fuelCMS-1.4.1-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/160080/Fuel-CMS-1.4-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/164756/Fuel-CMS-1.4.1-Remote-Code-Execution.html
Known exploited vulnerability sources
Catalogues that list this CVE as a known exploited vulnerability.
| Source | Added |
|---|---|
| The Shadowserver (via CIRCL) | Jun 06, 2025 |
Scanner integrations
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-16763.yaml | Apr 25, 2025 |
Potential proof of concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2025-04-13 00:45:30 UTC · 0 stars
The goal of this project was to conduct a security audit of a blog recently launched by Ackme Support Incorporated, identifying any critical vulnerabilities before the site goes public. The task involved finding a way to remotely execute code and gain access to the target system.
github · Created 2025-01-08 01:30:07 UTC · 0 stars
Fuel CMS 1.4.1 - Remote Code Execution
github · Created 2023-07-16 20:40:45 UTC · 0 stars
Fuel CMS 1.4.1 - Remote Code Execution - Python 3.x
github · Created 2023-06-09 13:01:48 UTC · 0 stars
github · Created 2023-01-03 20:47:08 UTC · 2 stars
CVE-2018-16763 FuelCMS 1.4 Remote Code Execution, this version of FuelCMS is still vulnerable until now
github · Created 2022-05-31 15:31:37 UTC · 13 stars
Exploit to trigger RCE for CVE-2018-16763 on FuelCMS <= 1.4.1 and interactive shell.
github · Created 2022-01-08 07:15:24 UTC · 2 stars
github · Created 2021-11-22 14:53:42 UTC · 0 stars
A write up on the THM room Vulnerability Capstone & Exploit script for CVE-2018-16763.
github · Created 2021-11-03 04:38:54 UTC · 5 stars
Fuel CMS 1.4.1 - Remote Code Execution
github · Created 2021-09-27 05:15:38 UTC · 2 stars
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.
github · Created 2020-10-10 20:23:59 UTC · 3 stars
github · Created 2020-09-03 15:06:22 UTC · 2 stars
This is an updated version of the CVE-2018-16763 for fuelCMS 1.4.1
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Proof of Concept Exploit Available
-
Detected by Nuclei
-
Added to KEVIntel