CVE-2005-2616

ezUpload 2.2 - Remote Code Execution via Path Parameter File Include

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2005-2616. PoCs published by Johnnie Walker.

AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in ezUpload by manipulating the 'path' parameter in 'initialize.php' to include arbitrary remote PHP code. The vulnerability arises from insufficient input sanitization, allowing an attacker to execute server-side script code with the privileges of the web server.

Description

Multiple PHP file include vulnerabilities in ezUpload 2.2 allow remote attackers to execute arbitrary code via the path parameter to (1) initialize.php, (2) customize.php, (3) form.php, or (4) index.php.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Johnnie Walker · textwebappsphp
https://www.exploit-db.com/exploits/26141

This exploit demonstrates a remote file inclusion vulnerability in ezUpload by manipulating the 'path' parameter in 'initialize.php' to include arbitrary remote PHP code. The vulnerability arises from insufficient input sanitization, allowing an attacker to execute server-side script code with the privileges of the web server.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: ezUpload (version not specified)
No auth needed
Prerequisites: Remote PHP shell accessible via URL · Target server with 'allow_url_include' enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Johnnie Walker · textwebappsphp
https://www.exploit-db.com/exploits/26140

This exploit demonstrates a remote file inclusion vulnerability in ezUpload due to improper input sanitization. An attacker can execute arbitrary server-side script code by manipulating the 'path' parameter in the URL.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: ezUpload (version not specified)
No auth needed
Prerequisites: Target server running ezUpload with vulnerable configuration · Ability to send HTTP requests to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Johnnie Walker · textwebappsphp
https://www.exploit-db.com/exploits/26143

This exploit demonstrates a remote file inclusion vulnerability in ezUpload by manipulating the 'path' parameter in form.php to include arbitrary remote PHP code. The vulnerability arises due to insufficient input sanitization, allowing an attacker to execute server-side script code with the privileges of the web server process.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: ezUpload (version not specified)
No auth needed
Prerequisites: Remote server hosting malicious PHP shell · Network access to the vulnerable ezUpload instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Johnnie Walker · textwebappsphp
https://www.exploit-db.com/exploits/26142

This exploit demonstrates a remote file inclusion vulnerability in ezUpload's customize.php script. By manipulating the 'path' parameter, an attacker can include and execute arbitrary remote PHP code, leading to remote code execution (RCE) with the privileges of the web server.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: ezUpload (version not specified)
No auth needed
Prerequisites: Remote PHP shell or script hosted on an attacker-controlled server · Target server must have allow_url_include enabled in PHP configuration
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/16434
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/14534
Exploit, Vendor Advisory x_refsource_misc
http://www.securiteam.com/exploits/5JP0J15GKU.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2005/1379
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1014723

Scores

EPSS 0.1145
EPSS Percentile 95.5%

Details

Status published
Products (1)
ezupload/ezupload 2.2
Published Aug 17, 2005
Tracked Since Feb 18, 2026