CVE-2008-6768
K&S Shopsoftware - Unauthenticated Arbitrary File Upload via Admin Image Editor
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6768. PoCs published by mNt.
AI-analyzed exploit summary This is a writeup describing a file upload vulnerability in Shopsysteme (a version of osCommerce). It outlines the steps to exploit the vulnerability to upload a PHP shell disguised as a GIF file, but does not include actual exploit code.
Description
Unrestricted file upload vulnerability in admin/editor/images.php in K&S Shopsoftware allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/upload/.
Exploits (1)
This is a writeup describing a file upload vulnerability in Shopsysteme (a version of osCommerce). It outlines the steps to exploit the vulnerability to upload a PHP shell disguised as a GIF file, but does not include actual exploit code.