CVE-2008-2267

CMS Made Simple <= 1.2.4 - Remote Code Execution via File Upload Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-2267. PoCs published by EgiX.

AI-analyzed exploit summary This exploit targets a file upload vulnerability in CMS Made Simple <= 1.2.4, allowing arbitrary file uploads due to insufficient extension filtering. It uploads a malicious PHP shell and provides interactive command execution.

Description

Incomplete blacklist vulnerability in javaUpload.php in Postlet in the FileManager module in CMS Made Simple 1.2.4 and earlier allows remote attackers to execute arbitrary code by uploading a file with a name ending in (1) .jsp, (2) .php3, (3) .cgi, (4) .dhtml, (5) .phtml, (6) .php5, or (7) .jar, then accessing it via a direct request to the file in modules/FileManager/postlet/.

Exploits (1)

exploitdb WORKING POC VERIFIED
by EgiX · phpwebappsphp
https://www.exploit-db.com/exploits/5600

This exploit targets a file upload vulnerability in CMS Made Simple <= 1.2.4, allowing arbitrary file uploads due to insufficient extension filtering. It uploads a malicious PHP shell and provides interactive command execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: CMS Made Simple <= 1.2.4
No auth needed
Prerequisites: Network access to the target · FileManager module enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/42371
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/29170
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30208
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5600
Third Party Advisory mailing-list x_refsource_vim
http://www.attrition.org/pipermail/vim/2008-May/001978.html

Scores

EPSS 0.0481
EPSS Percentile 90.8%

Details

CWE
CWE-20
Status published
Products (1)
cms_made_simple/cms_made_simple 1.2.4
Published May 16, 2008
Tracked Since Feb 18, 2026