{"id":"CVE-2018-19290","details":"In modules/HELPBOT_MODULE in Budabot 0.6 through 4.0, lax syntax validation allows remote attackers to perform a command injection attack against the PHP daemon with a crafted command, resulting in a denial of service or possibly unspecified other impact, as demonstrated by the \"!calc 5 x 5\" command. In versions before 3.0, modules/HELPBOT_MODULE/calc.php has the vulnerable code; in 3.0 and above, modules/HELPBOT_MODULE/HelpbotController.class.php has the vulnerable code.","modified":"2026-07-08T05:54:46.197537539Z","published":"2018-11-30T18:29:00.567Z","database_specific":{"unresolved_ranges":[{"vendor_product":"budabot:budabot","cpes":["cpe:2.3:a:budabot:budabot:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0.6"},{"last_affected":"4.0"}],"source":"CPE_RANGE"},{"extracted_events":[{"introduced":"0.6"},{"fixed":"4.0"}],"source":"DESCRIPTION"}]},"references":[{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/150391/Budabot-4.0-Denial-Of-Service.html"},{"type":"EVIDENCE","url":"http://seclists.org/fulldisclosure/2018/Nov/44"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/budabot/budabot","events":[{"introduced":"0"},{"fixed":"28e6d947574f8cc9914746274e6183df07a258d7"}],"database_specific":{"source":"DESCRIPTION","extracted_events":[{"introduced":"0"},{"fixed":"3.0"}]}}],"versions":["3.0_RC5","3.0_RC4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-19290.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}