Exploitation Summary
EIP tracks 1 public exploit for CVE-2005-1604. PoCs published by tjomi4.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in PHP Advanced Transfer Manager 1.21, allowing attackers to upload and execute malicious PHP scripts via a crafted filename (e.g., nst.php.ns) and command injection through the 'nst' GET parameter.
Description
PHP Advanced Transfer Manager (phpATM) 1.21 allows remote attackers to upload arbitrary files via filenames containing multiple file extensions, as demonstrated using a filename ending in "php.ns", which allows execution of arbitrary PHP code.
Exploits (1)
This exploit demonstrates an arbitrary file upload vulnerability in PHP Advanced Transfer Manager 1.21, allowing attackers to upload and execute malicious PHP scripts via a crafted filename (e.g., nst.php.ns) and command injection through the 'nst' GET parameter.