CVE-2008-5663

Kusaba < 1.0.4 - Authenticated Arbitrary File Upload via load_receiver.php or paint_save.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2008-5663. PoCs published by Sausage.

AI-analyzed exploit summary This exploit targets Kusaba <= 1.0.4 by uploading a malicious PHP file via the load_receiver.php script. The payload is a base64-encoded PHP backdoor that allows remote code execution if the attacker can access the uploaded file.

Description

Multiple unrestricted file upload vulnerabilities in Kusaba 1.0.4 and earlier allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension using (1) load_receiver.php or (2) a shipainter action to paint_save.php, then accessing the uploaded file via a direct request to this file in their user directory.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Sausage · htmlwebappsphp
https://www.exploit-db.com/exploits/6711

This exploit targets Kusaba <= 1.0.4 by uploading a malicious PHP file via the load_receiver.php script. The payload is a base64-encoded PHP backdoor that allows remote code execution if the attacker can access the uploaded file.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Kusaba <= 1.0.4
Auth required
Prerequisites: Access to load_receiver.php · Knowledge of the admin password (default: 'changeme')
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Sausage · phpwebappsphp
https://www.exploit-db.com/exploits/6706

This exploit targets Kusaba <= 1.0.4 by uploading a malicious PHP shell disguised as an image file. It leverages a file upload vulnerability in the paint_save.php endpoint to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Kusaba <= 1.0.4
No auth needed
Prerequisites: Access to the target's paint_save.php endpoint · Ability to upload files
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45793
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6706
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31668
Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31685
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6711
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4782
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45794

Scores

EPSS 0.0627
EPSS Percentile 92.7%

Details

CWE
CWE-20
Status published
Products (1)
kusaba/kusaba < 1.0.4
Published Dec 19, 2008
Tracked Since Feb 18, 2026