Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-3591. PoCs published by Raz0r.
AI-analyzed exploit summary This exploit leverages a SQL injection vulnerability in Symphony CMS <= 1.7.01 to bypass admin authentication and upload a malicious PHP file, enabling remote command execution. The PoC demonstrates a full attack chain from auth bypass to RCE via file upload.
Description
SQL injection vulnerability in lib/class.admin.php in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary SQL commands via the sym_auth cookie in a /publish/filemanager/ request to index.php.
Exploits (1)
This exploit leverages a SQL injection vulnerability in Symphony CMS <= 1.7.01 to bypass admin authentication and upload a malicious PHP file, enabling remote command execution. The PoC demonstrates a full attack chain from auth bypass to RCE via file upload.