Security Advisory

CVE-2018-25412

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-30 14:55:18
Last updated 2026-06-02 02:00:58
Assigner VulnCheck
CVSS score not scored
State PUBLISHED

Description

Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted multipart form data. Attackers can upload PHP files with arbitrary content to the upload directory and execute them on the server for remote code execution.