4782Third-party advisory
http://securityreason.com/securityalert/4782 CVE-2008-5663
Kusaba 1.0.4 - Remote Code Execution (1)
Record summary
CVE-2008-5663 has a selected CVSS score of 9.0; EIP currently links 2 catalogued exploits.
Description
Multiple unrestricted file upload vulnerabilities in Kusaba 1.0.4 and earlier allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension using (1) load_receiver.php or (2) a shipainter action to paint_save.php, then accessing the uploaded file via a direct request to this file in their user directory.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBKusaba 1.0.4 - Remote Code Execution (1)ExploitDB exploitby SausageNot analyzed1 file
ExploitDBKusaba 1.0.4 - Remote Code Execution (2)ExploitDB exploitby SausageNot analyzed1 file
References
831668vdb entry
http://www.securityfocus.com/bid/31668 31685vdb entry
http://www.securityfocus.com/bid/31685 kusaba-paintsave-code-execution(45793)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/45793 kusaba-loadreceiver-code-execution(45794)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/45794 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-5663 6706exploit
https://www.exploit-db.com/exploits/6706 6711exploit
https://www.exploit-db.com/exploits/6711