CVE-2008-3181
ContentNow CMS 1.4.1 - Authenticated Arbitrary File Upload via upload.php
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3181. PoCs published by CWH Underground.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability and a reflected XSS vulnerability in ContentNow CMS 1.4.1. The file upload allows attackers to upload malicious files directly to the server, while the XSS can be triggered via crafted URLs.
Description
Unrestricted file upload vulnerability in upload.php in ContentNow CMS 1.4.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in upload/.
Exploits (1)
This exploit demonstrates an arbitrary file upload vulnerability and a reflected XSS vulnerability in ContentNow CMS 1.4.1. The file upload allows attackers to upload malicious files directly to the server, while the XSS can be triggered via crafted URLs.