koogar.alorys-hebergement.comConfirmation
http://koogar.alorys-hebergement.com/kwsphp/index.php?mod=news&ac=commentaires&id=49 CVE-2008-6201
KwsPHP - 'Upload' Remote Code Execution
Record summary
CVE-2008-6201 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
Directory traversal vulnerability in help.php in the eskuel module in KwsPHP 1.3.456, as available before 20080416, allows remote attackers to execute arbitrary commands via the action parameter. NOTE: some of these details are obtained from third party information.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBKwsPHP - 'Upload' Remote Code ExecutionExploitDB exploitby AjaxNot analyzed1 file
References
829802Third-party advisory
http://secunia.com/advisories/29802 20080415 KwsPHP (Upload) Remote Code Execution Exploitmailing list
http://www.securityfocus.com/archive/1/490861 28788vdb entry
http://www.securityfocus.com/bid/28788 ADV-2008-1241vdb entry
http://www.vupen.com/english/advisories/2008/1241/references kwsphp-help-file-include(41950)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/41950 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-6201 5449exploit
https://www.exploit-db.com/exploits/5449