Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/hev0x/cve-2018-19422-subrioncms-rce
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubhev0x/cve-2018-19422-subrioncms-rce

CVE-2018-19422-SubrionCMS-RCE

CVE-2018-19422 Authenticated Remote Code Execution

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
8525 years agoNot yet reviewed
Share

CVE-2018-19422-SubrionCMS-RCE

SubrionCMS 4.2.1 Authenticated Remote Code Execution

  • /panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these.

Exploit Usage

Commands:

  • Windows/Linux: $ sudo python3 subrionRCE.py -u http://IP/panel/ -l <user> -p <password>

  • References:

    https://www.exploit-db.com/exploits/49876

    https://packetstormsecurity.com/files/162591/Subrion-CMS-4.2.1-Shell-Upload.html

    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19422

Download Tool