CVE-2003-1252

S8Forum 3.0 - Remote Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-1252. PoCs published by nmsh_sa.

AI-analyzed exploit summary This exploit leverages a file upload vulnerability in S8Forum's registration process to create a malicious PHP file. By injecting PHP code into the E-Mail field, an attacker can achieve remote command execution when the file is accessed via HTTP.

Description

register.php in S8Forum 3.0 allows remote attackers to execute arbitrary PHP commands by creating a user whose name ends in a .php extension and entering the desired commands into the E-mail field, which creates a web-accessible .php file that can be called by the attacker, as demonstrated using a "system($cmd)" E-mail address with a "any_name.php" username.

Exploits (1)

exploitdb WORKING POC VERIFIED
by nmsh_sa · textwebappsphp
https://www.exploit-db.com/exploits/22134

This exploit leverages a file upload vulnerability in S8Forum's registration process to create a malicious PHP file. By injecting PHP code into the E-Mail field, an attacker can achieve remote command execution when the file is accessed via HTTP.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: S8Forum
No auth needed
Prerequisites: Access to the registration page of S8Forum
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/7819
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1005881
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6547
Exploit, Vendor Advisory mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/305406
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10974.php
Exploit, Vendor Advisory mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0004.html

Scores

EPSS 0.0309
EPSS Percentile 86.4%

Details

Status published
Products (1)
kelli_shaver/s8forum 3.0
Published Dec 31, 2003
Tracked Since Feb 18, 2026