CVE-2008-6492
Tizag Countdown Creator 3 - Unauthenticated Arbitrary File Upload via index.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6492. PoCs published by ahmadbady.
AI-analyzed exploit summary This exploit demonstrates a remote file upload vulnerability in tizag-countdown_Version_3, allowing an attacker to upload a malicious PHP file to the server. The uploaded file can then be accessed to execute arbitrary code.
Description
Unrestricted file upload vulnerability in process.php in Tizag Countdown Creator 3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via index.php, then accessing the uploaded file via a direct request to the file in pics/. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates a remote file upload vulnerability in tizag-countdown_Version_3, allowing an attacker to upload a malicious PHP file to the server. The uploaded file can then be accessed to execute arbitrary code.