CVE-2008-6771
YourPlace <= 1.0.2 - Information Disclosure via phpinfo.php Direct Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6771. PoCs published by Osirys.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in YourPlace 0.5 (beta 1), including database disclosure, arbitrary data saving leading to RCE, arbitrary file upload, PHPInfo disclosure, and user account manipulation. The Perl script provided automates the RCE exploit by injecting malicious PHP code into a writable file.
Description
YourPlace 1.0.2 and earlier allows remote attackers to obtain sensitive system information via a direct request via a direct request to user/uploads/phpinfo.php, which calls the phpinfo function.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in YourPlace 0.5 (beta 1), including database disclosure, arbitrary data saving leading to RCE, arbitrary file upload, PHPInfo disclosure, and user account manipulation. The Perl script provided automates the RCE exploit by injecting malicious PHP code into a writable file.