Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted multipart form data. Attackers can upload PHP files with arbitrary content to the upload directory and execute them on the server for remote code execution.
References
| Link | Resource |
|---|---|
| http://deltasql.sourceforge.net/ | Product |
| http://deltasql.sourceforge.net/deltasql/ | Product |
| https://sourceforge.net/projects/deltasql/files/latest/download | Product |
| https://www.exploit-db.com/exploits/45685 | Exploit Third Party Advisory |
| https://www.vulncheck.com/advisories/delta-sql-arbitrary-file-upload-via-docs-upload-php | Third Party Advisory |
Configurations
History
03 Jun 2026, 19:26
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:deltasql_project:deltasql:1.8.2:*:*:*:*:*:*:* | |
| References | () http://deltasql.sourceforge.net/ - Product | |
| References | () http://deltasql.sourceforge.net/deltasql/ - Product | |
| References | () https://sourceforge.net/projects/deltasql/files/latest/download - Product | |
| References | () https://www.exploit-db.com/exploits/45685 - Exploit, Third Party Advisory | |
| References | () https://www.vulncheck.com/advisories/delta-sql-arbitrary-file-upload-via-docs-upload-php - Third Party Advisory | |
| First Time |
Deltasql Project deltasql
Deltasql Project |
30 May 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-30 16:17
Updated : 2026-06-03 19:26
NVD link : CVE-2018-25412
Mitre link : CVE-2018-25412
CVE.ORG link : CVE-2018-25412
JSON object : View
Products Affected
deltasql_project
- deltasql
CWE
CWE-306
Missing Authentication for Critical Function
