CVE-2006-3381
SturGeoN Upload - Unauthenticated Arbitrary PHP Code Execution via File Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-3381. PoCs published by Jihad BENABRA.
AI-analyzed exploit summary This exploit leverages an arbitrary file upload vulnerability in SturGeoN Upload v1 to upload a malicious PHP file containing a command execution payload. It then interacts with the uploaded file to execute system commands remotely.
Description
SturGeoN Upload allows remote attackers to execute arbitrary PHP code by uploading a file with a .php extension, then directly accessing the file. NOTE: It is uncertain whether this is a vulnerability or a feature of the product.
Exploits (1)
This exploit leverages an arbitrary file upload vulnerability in SturGeoN Upload v1 to upload a malicious PHP file containing a command execution payload. It then interacts with the uploaded file to execute system commands remotely.