S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2018-16763 Scanner

CVE-2018-16763 scanner - Remote Code Execution (RCE) vulnerability in fuel CMS

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-16763
9.8
CVSS

FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Fuel CMS is a popular content management system which has gained a lot of attention for its flexibility, functionality, and ease of use. Fuel CMS provides a wide range of features that make it an ideal choice for website designing and development. It is used by developers and businesses to create websites, blogs, and online stores. The CMS is open-source, which means that it is entirely free to use and customize, and developers can modify the system code according to their requirements.

One of the most recent and severe vulnerabilities discovered in Fuel CMS is CVE-2018-16763. This vulnerability allows for pre-authentication, remote code execution. It occurs due to the incorrect sanitization of user input in the pages/select/ filter parameter, allowing an attacker to execute arbitrary PHP code. It can also be exploited via the preview/ data parameter, which can be used to store malicious code.

Exploitation of this vulnerability can lead to unauthorized access to systems, data theft, and complete system compromise. Remote code execution vulnerabilities allow actors to run arbitrary code on a victim's system, providing them with complete control and access to all system data. This vulnerability poses a significant threat to the confidentiality, integrity, and availability of the affected system.

s4e.io provides enterprise-grade protection against vulnerabilities in digital assets. Their pro features allow users to scan their website and receive detailed reports of any vulnerabilities present. Users can quickly identify and fix any security issues, ensuring that their systems remain secure and protected. In conclusion, being vigilant and taking proactive steps to secure your web applications is essential in today's digital landscape.

 

REFERENCES

Solution Advice

To protect against CVE-2018-16763, the following precautions can be taken:

  • Update to the latest version of Fuel CMS
  • Scan your website regularly for any unusual activity or unauthorized access
  • Use a web application firewall to protect against SQL injection and other types of attacks
  • Follow secure coding practices and sanitize all user input
  • Keep all plugins and extensions up-to-date and remove any unused or unnecessary ones

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-16763 scanner - Remote Code Execution (RCE) vulnerability in fuel CMS | S4E