CVE-2008-6518
VidiScript - Authenticated Remote Code Execution via Avatar Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6518. PoCs published by InjEctOr5.
AI-analyzed exploit summary This is a writeup describing an arbitrary file upload vulnerability in VidiScript, allowing attackers to upload a shell (shell.php) via the avatar upload feature after authentication. The exploit requires user registration and login to execute.
Description
Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users to execute arbitrary code by uploading a PHP file as an Avatar, then accessing the avatar via a direct request.
Exploits (1)
This is a writeup describing an arbitrary file upload vulnerability in VidiScript, allowing attackers to upload a shell (shell.php) via the avatar upload feature after authentication. The exploit requires user registration and login to execute.