CVE-2008-6612
Minimal ABlog 0.4 - Unauthenticated Remote Code Execution via File Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6612. PoCs published by NoGe.
AI-analyzed exploit summary The exploit demonstrates SQL injection, file upload, and admin bypass vulnerabilities in minimal-ablog 0.4. It provides specific URLs and parameters to exploit these issues, including a demo SQL injection payload.
Description
Unrestricted file upload vulnerability in admin/uploader.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in img/.
Exploits (1)
The exploit demonstrates SQL injection, file upload, and admin bypass vulnerabilities in minimal-ablog 0.4. It provides specific URLs and parameters to exploit these issues, including a demo SQL injection payload.