Monstra CMS 3.0.4 CVE-2018-9037 – Remote Code Execution

Authors:JameelNabbo          Risk:High

CVE:CVE-2018-9037           0day:Remote Code Execution 

0day -id:0DAY-176183         Date:2018-05-15


Monstra CMS 3.0.4 allows remote code execution via an upload_file request for a .zip file, which is automatically extracted and may contain .php files.


# Exploit Title: Monstra CMS 3.0.4 Upload Plugin Remote code execution CVE-2018-9037
# Date: 2018-05-14
# Exploit Author: Jameel Nabbo
# Vendor Homepage:
# Software Link:
# Version: 3.0.4
# Tested on: MAC OSX
# CVE :CVE-2018-9037

Steps to Reproduce
1: Log in as a user with page editing permissions
2: Upload a plugin archive containing php webshell code
3: After successful upload we can execute the command.
Then go to:{Name_Of_Zip_File_You_Uploaded}/{File_In_Zip}.php



Filter plugin content during plugin upload

