CVE-2008-3117

PHPmotion <2.0 - RCE

Title source: llm

Description

Unrestricted file upload vulnerability in update_profile.php in PHPmotion 2.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a .php file with a content type of (1) image/gif, (2) image/jpeg, or (3) image/pjpeg, then accessing it via a direct request to the file under pictures/.

Exploits (1)

exploitdb WORKING POC VERIFIED
by EgiX · phpwebappsphp
https://www.exploit-db.com/exploits/5938

Scores

EPSS 0.0301
EPSS Percentile 86.6%

Details

CWE
CWE-20
Status published
Products (2)
phpmotion/phpmotion 1.0
phpmotion/phpmotion < 2.0
Published Jul 10, 2008
Tracked Since Feb 18, 2026