/claim #14587

PR Information

This pull request adds a robust nuclei template for detecting CVE-2018-9206, an unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0.

Key Features:

  • Tests 11 common installation paths for maximum coverage
  • Extracts uploaded file URL from server’s JSON response
  • Verifies file content accessibility for reliable detection
  • Handles PHP warnings gracefully with improved matcher logic
  • Includes comprehensive testing environment with Docker

References:

Template validation

  • Validated with a host running a vulnerable version and/or configuration (True Positive)

Additional Details

Template validated using a local Docker environment running jQuery-File-Upload v9.22.0.

Additional References:

Claim

Total prize pool $100,100
Total paid $0
Status Pending
Submitted January 01, 2026
Last updated January 01, 2026

Contributors

SY

Syed Azeez

@syedazeez337-gmail-com

100%

Sponsors

MO

Mohammed Anas Nathani

@MohammedAnasNathani

$100,000
PR

ProjectDiscovery

@projectdiscovery

$100