{"id":"CVE-2018-25412","title":"Delta Sql 1.8.2 Arbitrary File Upload via docs_upload.php","summary":"Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted multipart form data. Attackers can upload PHP files …","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","cwe":["CWE-306"],"vendor":"Deltasql","product":"Delta Sql","affected":["delta_sql 1.8.2"],"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"total","timestamp":"2026-06-02T02:00:45.460759Z"},"exploitAvailable":true,"published":"2026-05-30","updated":"2026-10-01","sourceUpdated":"2026-10-01T15:19:15.802Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2018-25412","references":[{"url":"https://www.exploit-db.com/exploits/45685","label":"ExploitDB-45685"},{"url":"http://deltasql.sourceforge.net/","label":"Official Product Homepage"},{"url":"https://sourceforge.net/projects/deltasql/files/latest/download","label":"Product Reference"},{"url":"http://deltasql.sourceforge.net/deltasql/","label":"Product Reference"},{"url":"https://www.vulncheck.com/advisories/delta-sql-arbitrary-file-upload-via-docs-upload-php","label":"VulnCheck Advisory: Delta Sql 1.8.2 Arbitrary File Upload via docs_upload.php"}],"tags":["cve.org","exploit-available"],"epss":0.00771,"epssPercentile":0.54008,"ingestedAt":"2026-10-01T15:48:17.886Z","slug":"CVE-2018-25412","body":"## Overview\n\nDelta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted multipart form data. Attackers can upload PHP files with arbitrary content to the upload directory and execute them on the server for remote code execution.\n\n## Affected\n\n- `delta_sql 1.8.2`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":66,"depthScoreParts":{"impact":53.9,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[]}