CVE-2008-3592

Twentyone Degrees Symphony <1.7.01 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-3592. PoCs published by Raz0r.

AI-analyzed exploit summary This exploit leverages a SQL injection vulnerability in Symphony CMS <= 1.7.01 to bypass admin authentication and upload a malicious PHP file, enabling remote command execution. The PoC demonstrates a full attack chain from auth bypass to RCE via file upload.

Description

Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to a directory specified in the destination parameter, then accessing the uploaded file via a direct request, as demonstrated using workspace/masters/.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Raz0r · phpwebappsphp
https://www.exploit-db.com/exploits/6177

This exploit leverages a SQL injection vulnerability in Symphony CMS <= 1.7.01 to bypass admin authentication and upload a malicious PHP file, enabling remote command execution. The PoC demonstrates a full attack chain from auth bypass to RCE via file upload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Symphony CMS <= 1.7.01
No auth needed
Prerequisites: Target must be running Symphony CMS <= 1.7.01 · File upload functionality must be accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6177
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/44432
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4137
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31293

Scores

EPSS 0.0681
EPSS Percentile 93.2%

Details

CWE
CWE-94
Status published
Products (7)
21degrees/symphony 1.1
21degrees/symphony 1.5
21degrees/symphony 1.5.05
21degrees/symphony 1.5.06
21degrees/symphony 1.6.02
21degrees/symphony 1.7
21degrees/symphony < 1.7.01
Published Aug 11, 2008
Tracked Since Feb 18, 2026