CVE-2018-25412
Delta Sql 1.8.2 Arbitrary File Upload via docs_upload.php
CVSS Score
9.8
EPSS Score
0.2%
EPSS Percentile
39th
Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted multipart form data. Attackers can upload PHP files with arbitrary content to the upload directory and execute them on the server for remote code execution.
| CWE | CWE-306 |
| Vendor | deltasql |
| Product | delta sql |
| Published | May 30, 2026 |
| Last Updated | Jun 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for deltasql delta sql
Be the first to know when new critical vulnerabilities affecting deltasql delta sql are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Deltasql / Delta Sql
1.8.2
References
exploit-db.com: https://www.exploit-db.com/exploits/45685 deltasql.sourceforge.net: http://deltasql.sourceforge.net/ sourceforge.net: https://sourceforge.net/projects/deltasql/files/latest/download deltasql.sourceforge.net: http://deltasql.sourceforge.net/deltasql/ vulncheck.com: https://www.vulncheck.com/advisories/delta-sql-arbitrary-file-upload-via-docs-upload-php
Credits
Ihsan Sencan