CVE-2008-6201

KwsPHP 1.3.456 - Path Traversal via Help.php Action Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6201. PoCs published by Ajax.

AI-analyzed exploit summary This PHP script exploits CVE-2008-6201, a remote code execution vulnerability in KwsPHP. It authenticates with provided credentials, uploads a malicious PHP file disguised as an image, and executes it via a path traversal vulnerability.

Description

Directory traversal vulnerability in help.php in the eskuel module in KwsPHP 1.3.456, as available before 20080416, allows remote attackers to execute arbitrary commands via the action parameter. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Ajax · phpwebappsphp
https://www.exploit-db.com/exploits/5449

This PHP script exploits CVE-2008-6201, a remote code execution vulnerability in KwsPHP. It authenticates with provided credentials, uploads a malicious PHP file disguised as an image, and executes it via a path traversal vulnerability.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: KwsPHP (All Versions)
Auth required
Prerequisites: Valid KwsPHP user credentials · Ability to upload files · Target server with KwsPHP installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5449
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29802
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1241/references
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41950
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/490861
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28788

Scores

EPSS 0.0306
EPSS Percentile 85.9%

Details

CWE
CWE-22
Status published
Products (1)
kwsphp/kwsphp 1.3.456
Published Feb 20, 2009
Tracked Since Feb 18, 2026