CVE-2008-4878
WebCards < 1.3 - Authenticated Arbitrary File Upload via Add Image Macro
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4878. PoCs published by t0pP8uZz.
AI-analyzed exploit summary This document describes a SQL injection vulnerability in WebCards <= 1.3, allowing remote attackers to bypass admin authentication by injecting SQL syntax into the login fields. It also outlines a method to upload a shell via the admin panel.
Description
Unrestricted file upload vulnerability in the "Add Image Macro" feature in WebCards 1.3 allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the uploaded file.
Exploits (1)
This document describes a SQL injection vulnerability in WebCards <= 1.3, allowing remote attackers to bypass admin authentication by injecting SQL syntax into the login fields. It also outlines a method to upload a shell via the admin panel.