Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2018-20718 | Kitploit
Tools/GitHubGitHub/us3r777/cve-2018-20718
Vulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationPenetration TestingRemote Access Tool
GitHubus3r777/cve-2018-20718

CVE-2018-20718

View Repository
37 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2018-20718

This is a POC for CVE-2018-20718. It is a PHP Object injection vulnerability. The vulnerability affect all version of Pydio before 8.2.1 and leads to Unauthenticated Remote Code Execution. It was originaly found by RIPS.

I found a gadget in Pydio\Core\Controller\ShutdownScheduler which allows remote code execution if combined with the already known GuzzleHttp\Psr7\FnStream gadget.

Exemple of exploitation

image image

Technical details

https://blog.ripstech.com/2018/pydio-unauthenticated-remote-code-execution/

Download Tool