CVE-2008-3117
PHPmotion <2.0 - RCE
Title source: llmDescription
Unrestricted file upload vulnerability in update_profile.php in PHPmotion 2.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a .php file with a content type of (1) image/gif, (2) image/jpeg, or (3) image/pjpeg, then accessing it via a direct request to the file under pictures/.
Exploits (1)
Scores
EPSS
0.0301
EPSS Percentile
86.6%
Details
CWE
CWE-20
Status
published
Products (2)
phpmotion/phpmotion
1.0
phpmotion/phpmotion
< 2.0
Published
Jul 10, 2008
Tracked Since
Feb 18, 2026