CVE-2006-1704

Sire 2.0 - Unauthenticated Arbitrary File Upload via upload.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-1704. PoCs published by simo64.

AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in SIRE, allowing an attacker to upload and execute arbitrary code on the webserver. The provided HTML form targets the 'upload.php' endpoint without authentication.

Description

Sire 2.0 nws allows remote attackers to upload arbitrary image files without authentication via a direct request to upload.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by simo64 · textwebappsphp
https://www.exploit-db.com/exploits/27592

This exploit demonstrates an arbitrary file upload vulnerability in SIRE, allowing an attacker to upload and execute arbitrary code on the webserver. The provided HTML form targets the 'upload.php' endpoint without authentication.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: SIRE (version not specified)
No auth needed
Prerequisites: Access to the vulnerable 'upload.php' endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17431
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015885
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25727
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/430301/100/0/threaded

Scores

EPSS 0.0238
EPSS Percentile 81.7%

Details

Status published
Products (1)
hubert_plisson/sire 2.0
Published Apr 11, 2006
Tracked Since Feb 18, 2026