CVE-2007-5305

ELSEIF CMS Beta 0.6 - Remote Code Execution via PHP File Inclusion

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-5305.

AI-analyzed exploit summary This exploit demonstrates a file upload vulnerability in Else If CMS Beta 0.6, allowing an attacker to upload a malicious PHP shell via the 'swfupload/upload.php' endpoint. The exploit constructs a multipart/form-data POST request to bypass restrictions and achieve remote code execution.

Description

Multiple PHP remote file inclusion vulnerabilities in ELSEIF CMS Beta 0.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) contenus parameter to (a) contenus.php; the (2) tpelseifportalrepertoire parameter to (b) votes.php, (c) espaceperso.php, (d) enregistrement.php, (e) commentaire.php, and (f) coeurusr.php in utilisateurs/, and (g) articles/fonctions.php and (h) depot/fonctions.php in moduleajouter/; the (3) corpsdesign parameter to (i) articles/usrarticles.php and (j) depot/usrdepot.php in moduleajouter/; and possibly other files.

Exploits (1)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/4490

This exploit demonstrates a file upload vulnerability in Else If CMS Beta 0.6, allowing an attacker to upload a malicious PHP shell via the 'swfupload/upload.php' endpoint. The exploit constructs a multipart/form-data POST request to bypass restrictions and achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Else If CMS Beta 0.6
No auth needed
Prerequisites: Network access to the target · File upload endpoint accessible
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (14)

Core 14
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/25951
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/37011
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38656
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38649
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38651
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38653
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38652
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38658
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38654
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38650
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38655
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/481683/100/0/threaded
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3204
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/38657

Scores

EPSS 0.0930
EPSS Percentile 94.7%

Details

CWE
CWE-94
Status published
Products (1)
yannick_tanguy/else_if_cms 0.6-beta
Published Oct 09, 2007
Tracked Since Feb 18, 2026