7.5
CVSSv3

CVE-2018-12053

Published: 08/06/2018 Updated: 17/07/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

Arbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.php by using directory traversal.

Vulnerable Product Search on Vulmon Subscribe to Product

schools alert management script project schools alert management script -

Exploits

# Exploit Title: Schools Alert Management Script - Arbitrary File Deletion # Date: 2018-06-07 # Vendor Homepage: wwwphpscriptsmallcom/ # Software Link: wwwphpscriptsmallcom/product/schools-alert-management-system/ # Category: Web Application # Exploit Author: M3@Pandas # Web: githubcom/unh3x/just4cve/issues/6 # Tested o ...
Schools Alert Management Script suffers from an arbitrary file deletion vulnerability ...