CVE-2008-1790
iScripts SocialWare - Authenticated Arbitrary File Upload via Logo File
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1790. PoCs published by t0pP8uZz.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in iScripts SocialWare, allowing an attacker to extract admin and user credentials from the database via crafted UNION-based SQL queries. The PoC includes specific injection payloads and a method to upload a shell post-exploitation.
Description
Unrestricted file upload vulnerability in iScripts SocialWare allows remote authenticated administrators to upload arbitrary files via a crafted logo file in the "Manage Settings" functionality. NOTE: remote exploitation is facilitated by a separate SQL injection vulnerability.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in iScripts SocialWare, allowing an attacker to extract admin and user credentials from the database via crafted UNION-based SQL queries. The PoC includes specific injection payloads and a method to upload a shell post-exploitation.