S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2018-19458 Scanner

CVE-2018-19458 scanner - Local File Inclusion (LFI) vulnerability in PHP Proxy

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
6.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-19458
7.5
CVSS

In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI URI, a different vulnerability than CVE-2018-19246.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Sep 14, 2026View on NVD →
Detail

PHP Proxy is a software product designed to work as a proxy server for PHP applications. The purpose of PHP Proxy is to allow users to bypass existing firewalls and access PHP applications that are usually blocked by default. This software also provides a secure connection to the application server, protecting users' data and privacy.

The CVE-2018-19458 vulnerability was detected in PHP Proxy version 3.0.3. This vulnerability is due to an LFI URI, which allows any user to read files from the server without authentication. This is a different vulnerability from CVE-2018-19246, which has already been resolved. The vulnerability code for CVE-2018-19458 is index.php?q=file:///.

When this vulnerability is exploited, attackers can access sensitive files and data from the server, including configuration files, usernames, and passwords. Attackers can use this information to escalate their attack and gain control of the server or other connected devices. This can result in a complete compromise of the system, leading to a loss of data and resources, as well as reputational damage.

At s4e.io, we offer pro features that allow users to quickly and easily identify vulnerabilities in their digital assets. Our platform provides comprehensive scanning and detection capabilities, as well as expert guidance and support to help users protect their assets against emerging threats. With our advanced tools and technologies, you can stay ahead of the curve and safeguard your digital assets against vulnerabilities like CVE-2018-19458.

 

REFERENCES

Solution Advice

To protect against CVE-2018-19458, users can take the following precautions:

  • Update to the latest version of PHP Proxy.
  • Use file system permissions to restrict access to sensitive files and directories.
  • Use external firewalls to block unauthorized access to the server.
  • Limit the use of third-party scripts and plugins that may introduce vulnerabilities.
  • Enable logging and monitoring to detect and respond to suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.