CVE-2018-19290
Dashboard / Vulnerabilities / CVE-2018-19290
CVE-2018-19290
Published: 30 Nov 2018Last Modified: 8 Jul 2026
Summary:
Details: In modules/HELPBOT_MODULE in Budabot 0.6 through 4.0, lax syntax validation allows remote attackers to perform a command injection attack against the PHP daemon with a crafted command, resulting in a denial of service or possibly unspecified other impact, as demonstrated by the "!calc 5 x 5" command. In versions before 3.0, modules/HELPBOT_MODULE/calc.php has the vulnerable code; in 3.0 and above, modules/HELPBOT_MODULE/HelpbotController.class.php has the vulnerable code.
References: http://packetstormsecurity.com/files/150391/Budabot-4.0-Denial-Of-Service.html, http://seclists.org/fulldisclosure/2018/Nov/44
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
3.0_RC5
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
