Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-2777. PoCs published by BlackHawk.
AI-analyzed exploit summary This exploit targets a file upload vulnerability in AlstraSoft Template Seller Pro <= 3.25, allowing remote code execution by uploading a malicious JPEG file with embedded PHP code. The script constructs a malicious image file and sends it to the vulnerable endpoint to achieve command execution.
Description
Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier allows remote attackers to execute arbitrary PHP code via an arbitrary .php filename in the zip parameter, which is created under sptemplates/.
Exploits (1)
This exploit targets a file upload vulnerability in AlstraSoft Template Seller Pro <= 3.25, allowing remote code execution by uploading a malicious JPEG file with embedded PHP code. The script constructs a malicious image file and sends it to the vulnerable endpoint to achieve command execution.