CVE-2007-0972

Jupiter CMS 1.1.5 - Unauthenticated Arbitrary File Upload via Emoticons Module

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-0972. PoCs published by DarkFig.

AI-analyzed exploit summary This exploit targets a file upload vulnerability in Jupiter CMS 1.1.5, allowing an attacker to upload a malicious PHP file by bypassing file type restrictions. The PoC uses a custom `phpsploit` class to craft a multipart/form-data request and retrieve the uploaded file.

Description

Unrestricted file upload vulnerability in modules/emoticons.php in Jupiter CMS 1.1.5 allows remote attackers to upload arbitrary files by modifying the HTTP request to send an image content type, and to omit is_guest and is_user parameters. NOTE: this issue might be related to CVE-2006-4875.

Exploits (1)

exploitdb WORKING POC VERIFIED
by DarkFig · phpwebappsphp
https://www.exploit-db.com/exploits/3311

This exploit targets a file upload vulnerability in Jupiter CMS 1.1.5, allowing an attacker to upload a malicious PHP file by bypassing file type restrictions. The PoC uses a custom `phpsploit` class to craft a multipart/form-data request and retrieve the uploaded file.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Jupiter CMS 1.1.5
No auth needed
Prerequisites: Network access to the target Jupiter CMS instance · File upload functionality enabled in the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Vendor Advisory x_refsource_misc
http://mgsdl.free.fr/advisories/12070214.txt
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/22560
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/3311
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/460076/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/32517
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/460100/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/33728
Vendor Advisory x_refsource_misc
http://www.acid-root.new.fr/advisories/12070214.txt

Scores

EPSS 0.0323
EPSS Percentile 86.6%

Details

Status published
Products (1)
jupiter_cms/jupiter_cms 1.1.5
Published Feb 16, 2007
Tracked Since Feb 18, 2026