CVE-2008-3592

Twentyone Degrees Symphony <1.7.01 - RCE

Title source: llm

Description

Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension to a directory specified in the destination parameter, then accessing the uploaded file via a direct request, as demonstrated using workspace/masters/.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Raz0r · phpwebappsphp
https://www.exploit-db.com/exploits/6177

Scores

EPSS 0.0609
EPSS Percentile 90.8%

Details

CWE
CWE-94
Status published
Products (7)
21degrees/symphony 1.1
21degrees/symphony 1.5
21degrees/symphony 1.5.05
21degrees/symphony 1.5.06
21degrees/symphony 1.6.02
21degrees/symphony 1.7
21degrees/symphony < 1.7.01
Published Aug 11, 2008
Tracked Since Feb 18, 2026