Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-19518

90
FAUCET Score

CVE-2018-19518 describes an argument injection vulnerability in the University of Washington IMAP Toolkit 2007f, specifically within its rsh command execution via imap_rimap and tcp_aopen functions. This flaw, affecting products like PHP's imap_open(), allows remote attackers to execute arbitrary OS commands if an untrusted IMAP server name is provided and rsh has been replaced by a program with different argument semantics (e.g., ssh). With a CVSS score of 7.5 (High), this vulnerability has a network attack vector, high attack complexity, and can lead to complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, a Metasploit module exists for this vulnerability, indicating readily available exploit code, though there is minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.6.0, <= 5.6.38CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
>= 7.0.0, <= 7.0.32CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
>= 7.1.0, <= 7.1.24CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
>= 7.2.0, <= 7.2.12CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.6
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
95.23%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Metasploit: php imap_open Remote Code Execution · Oct 23, 2018
Nuclei: CVE-2018-19518 · Mar 17, 2024
ExploitDB: EDB-45914 · Nov 29, 2018
This CVE's current EPSS score of 0.9523 is in the 100th percentile among its peer group of 1,160 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: php
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: php53
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: php
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: rh-php70-php

Vendor Advisories (1)

redhatCVE-2018-19518Moderate

php: imap_open() allows running arbitrary shell commands via mailbox parameter

Nov 19, 2018

References

antichat.com / threads/463395
ExploitThird Party Advisory
bugs.debian.org / 913775
Mailing ListThird Party Advisory
bugs.debian.org / 913835
Mailing ListThird Party Advisory
bugs.debian.org / 913836
Mailing ListThird Party Advisory
bugs.php.net / bug.php
ExploitMailing ListVendor Advisory
bugs.php.net / bug.php
ExploitMailing ListVendor Advisory
bugs.php.net / bug.php
Vendor Advisory
github.com / Bo0oM/PHP_imap_open_exploit/blob/master/exploit.php
ExploitThird Party Advisory
git.php.net
lists.debian.org / debian-lts-announce/2018/12/msg00006.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2019/03/msg00001.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2021/12/msg00031.html
Mailing ListThird Party Advisory
security.gentoo.org / glsa/202003-57
Third Party Advisory
security.netapp.com / advisory/ntap-20181221-0004
Third Party Advisory
usn.ubuntu.com / 4160-1
Third Party Advisory
debian.org / security/2018/dsa-4353
Third Party Advisory
exploit-db.com / exploits/45914
ExploitThird Party AdvisoryVDB Entry
openwall.com / lists/oss-security/2018/11/22/3
ExploitMailing ListThird Party Advisory
securityfocus.com / bid/106018
Broken Link
securitytracker.com / id/1042157
Broken Link