CVE-2008-0805
PHPizabi 0.848b C1 HFP1 - Unauthenticated Arbitrary File Upload and Remote Code Execution via Event Page Image Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0805. PoCs published by ZoRLu.
AI-analyzed exploit summary This exploit leverages a file upload vulnerability in PHPizabi v0.848b C1 HFP1, allowing an attacker to upload a malicious PHP shell via the event creation feature. The shell can then be accessed directly through a predictable path in the cache directory.
Description
Unrestricted file upload vulnerability in image.php in PHPizabi 0.848b C1 HFP1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension from the event page, then accessing it via a direct request to the file in system/cache/pictures.
Exploits (1)
This exploit leverages a file upload vulnerability in PHPizabi v0.848b C1 HFP1, allowing an attacker to upload a malicious PHP shell via the event creation feature. The shell can then be accessed directly through a predictable path in the cache directory.