CVE-2006-1704
Sire 2.0 - Unauthenticated Arbitrary File Upload via upload.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-1704. PoCs published by simo64.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in SIRE, allowing an attacker to upload and execute arbitrary code on the webserver. The provided HTML form targets the 'upload.php' endpoint without authentication.
Description
Sire 2.0 nws allows remote attackers to upload arbitrary image files without authentication via a direct request to upload.php.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by simo64 · textwebappsphp
https://www.exploit-db.com/exploits/27592
This exploit demonstrates an arbitrary file upload vulnerability in SIRE, allowing an attacker to upload and execute arbitrary code on the webserver. The provided HTML form targets the 'upload.php' endpoint without authentication.
Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:
SIRE (version not specified)
No auth needed
Prerequisites:
Access to the vulnerable 'upload.php' endpoint
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (4)
Core 4
Core References
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/17431
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1015885
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25727
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/430301/100/0/threaded
Scores
EPSS
0.0238
EPSS Percentile
81.7%
Details
Status
published
Products (1)
hubert_plisson/sire
2.0
Published
Apr 11, 2006
Tracked Since
Feb 18, 2026