CVE-2008-6773
YourPlace <= 1.0.2 - Authenticated Static Code Injection via Internet Toolbar Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6773. PoCs published by Osirys.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in YourPlace 0.5 (beta 1), including database disclosure, arbitrary data saving leading to RCE, arbitrary file upload, PHPInfo disclosure, and user account manipulation. The Perl script provided automates the RCE exploit by injecting malicious PHP code into a writable file.
Description
Static code injection vulnerability in user/internettoolbar/edit.php in YourPlace 1.0.2 and earlier allows remote authenticated users to execute arbitrary PHP code into user/internettoolbar/index.php via the (1) fav1_url, (2) fav1_name, (3) fav2_url, (4) fav2_name, (5) fav3_url, (6) fav3_name, (7) fav4_url, (8) fav4_name, (9) fav5_url, or (10) fav5_name parameters.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in YourPlace 0.5 (beta 1), including database disclosure, arbitrary data saving leading to RCE, arbitrary file upload, PHPInfo disclosure, and user account manipulation. The Perl script provided automates the RCE exploit by injecting malicious PHP code into a writable file.