CVE-2006-5016
e-Vision CMS - Unauthenticated Arbitrary File Upload via admin/x_image.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5016.
AI-analyzed exploit summary This exploit demonstrates SQL injection and remote file upload vulnerabilities in eVision 2.0. It includes specific URLs for blind SQL injection, credential extraction, and a file upload form to achieve remote code execution.
Description
Unrestricted file upload vulnerability in admin/x_image.php in Szava Gyula and Csaba Tamas e-Vision CMS, probably 1.0, allows remote attackers to upload arbitrary files to the /imagebank directory.
Exploits (1)
This exploit demonstrates SQL injection and remote file upload vulnerabilities in eVision 2.0. It includes specific URLs for blind SQL injection, credential extraction, and a file upload form to achieve remote code execution.