CVE-2008-4873
EXPLOITEDSepal SPBOARD 4.5 - Remote Command Execution via board.cgi file Parameter
Title source: llmExploitation Summary
CVE-2008-4873 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including GoLd_M.
AI-analyzed exploit summary This exploit demonstrates a remote command execution vulnerability in Sepal's SPBOARD v4.5 via the 'file' parameter in board.cgi. The PoC shows how arbitrary commands can be injected and executed through the 'down_file' action.
Description
board.cgi in Sepal SPBOARD 4.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter during a down_file action.
Exploits (1)
This exploit demonstrates a remote command execution vulnerability in Sepal's SPBOARD v4.5 via the 'file' parameter in board.cgi. The PoC shows how arbitrary commands can be injected and executed through the 'down_file' action.