S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Aug 21, 2025

CVE-2018-19127 Scanner

CVE-2018-19127 Scanner - Remote Code Execution (RCE) vulnerability in PHPCMS 2008

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-19127
9.8
CVSS

A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a controllable filename, leading to arbitrary code execution. The PHP code is sent via the template parameter, and is written to a data/cache_template/*.tpl.php file along with a "<?php function " substring.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

PHPCMS 2008 is a content management system used by web developers for facilitating the creation, management, and modification of digital content on websites. Designed for ease of use, it provides tools for managing and configuring the web content and is popular for its comprehensive set of features for building complex websites. Organizations utilize PHPCMS 2008 to efficiently share and manage their information online. Despite its popularity, PHPCMS 2008 has become obsolete, with numerous security vulnerabilities due to lack of maintenance. Users leveraging PHPCMS 2008 have to consider the risks due to these vulnerabilities. It remains crucial for administrators to continuously monitor systems built on such outdated platforms.

The Remote Code Execution (RCE) vulnerability in PHPCMS 2008 is a critical security flaw that allows attackers to execute arbitrary code on the host server. Such vulnerabilities exist when an application inadvertently allows remote execution of arbitrary commands supplied by the attacker. This vulnerability occurs due to weak template injection handling, which fails to properly sanitize user-supplied data. When this data is incorporated into a template, it can introduce and execute malicious code. Consequently, it provides attackers a vector to exploit the server-side logic and take unauthorized actions.

The RCE vulnerability in this scenario arises from an insecure implementation in the 'type.php' file in PHPCMS 2008. The flaw is a result of improper validation of template inputs, where attacker-supplied content is written into a PHP template cache file. As the cached file is processed by the system, the unsanitized input enables execution of arbitrary PHP code. These actions offer attackers the potential to gain substantial control over server resources. For successful exploitation, attackers can trigger payloads through crafted URLs targeting vulnerable endpoints.

Exploitation of this vulnerability enables attackers to fully compromise the server by gaining the ability to execute arbitrary commands. The potential effects are severe, allowing attackers to modify, delete or exfiltrate data, disrupt services, or deploy further malicious tools or malware. Without proper mitigations, attackers might leverage this vulnerability to cause significant data breaches or disrupt business operations. Beyond unauthorized access, it could also lead to tangential risks, such as reputational damage or compliance violations for the affected organizations.

REFERENCES

Solution Advice
  • Immediately upgrade to a maintained CMS solution to mitigate risks associated with outdated software.
  • Restrict public access to PHPCMS 2008 installations and isolate them from other critical network components.
  • Implement web application firewalls to detect and block attempted template injections.
  • Employ intrusion detection systems to monitor and alert any unauthorized file manipulations.
  • Regularly audit systems for signs of compromise and ensure all systems are running the latest security patches.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.