CVE-2008-6119
Goople CMS 1.7 - Static Code Injection via Username and Password Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6119. PoCs published by BeyazKurt.
AI-analyzed exploit summary This exploit leverages an authentication bypass vulnerability in Goople CMS 1.7 by setting a 'loggedin' cookie via JavaScript, allowing unauthorized file uploads. The attacker can then upload malicious files (e.g., PHP/HTML) to achieve remote code execution.
Description
Static code injection vulnerability in gooplecms/admin/account/action/editpass.php in Goople CMS 1.7 allows remote attackers to inject arbitrary PHP code into admin/userandpass.php via the (1) username and (2) password parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This exploit leverages an authentication bypass vulnerability in Goople CMS 1.7 by setting a 'loggedin' cookie via JavaScript, allowing unauthorized file uploads. The attacker can then upload malicious files (e.g., PHP/HTML) to achieve remote code execution.