CVE-2008-1958
Tr Script News 2.1 - Authenticated Remote Code Execution via File Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1958. PoCs published by His0k4.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Tr Script News v2.1 via the 'nb' parameter in news.php. It allows an attacker to extract sensitive information such as usernames, passwords, and emails from the database.
Description
Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authenticated users to execute arbitrary code by uploading a file with a .php extension.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Tr Script News v2.1 via the 'nb' parameter in news.php. It allows an attacker to extract sensitive information such as usernames, passwords, and emails from the database.