CVE-2008-6518

VidiScript - Authenticated Remote Code Execution via Avatar Upload

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6518. PoCs published by InjEctOr5.

AI-analyzed exploit summary This is a writeup describing an arbitrary file upload vulnerability in VidiScript, allowing attackers to upload a shell (shell.php) via the avatar upload feature after authentication. The exploit requires user registration and login to execute.

Description

Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users to execute arbitrary code by uploading a PHP file as an Avatar, then accessing the avatar via a direct request.

Exploits (1)

exploitdb WRITEUP VERIFIED
by InjEctOr5 · textwebappsphp
https://www.exploit-db.com/exploits/6259

This is a writeup describing an arbitrary file upload vulnerability in VidiScript, allowing attackers to upload a shell (shell.php) via the avatar upload feature after authentication. The exploit requires user registration and login to execute.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: VidiScript (version unspecified)
Auth required
Prerequisites: User registration on the target site · Valid login credentials · Access to the profile avatar upload feature
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6259
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30721
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/44525

Scores

EPSS 0.0330
EPSS Percentile 86.9%

Details

CWE
CWE-94
Status published
Products (1)
vidiscript/vidiscript
Published Mar 25, 2009
Tracked Since Feb 18, 2026