CVE-2008-4428

Phlatline Personal Information Manager - Improper Input Validation

Title source: rule

Description

Unrestricted file upload vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier allows remote attackers to execute arbitrary code by uploading a .php file, then accessing it via a direct request to the file in the top-level directory.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Stack · textwebappsphp
https://www.exploit-db.com/exploits/6231
exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/8105
exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/6215

Scores

EPSS 0.0718
EPSS Percentile 91.6%

Details

CWE
CWE-20
Status published
Products (1)
phlatline/personal_information_manager < 1.0
Published Oct 03, 2008
Tracked Since Feb 18, 2026