CVE-2008-6814

com_simpleboard < 1.0.1 - Unauthenticated Arbitrary File Upload via image_upload.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6814. PoCs published by t0pP8uZz.

AI-analyzed exploit summary This exploit targets a file upload vulnerability in SimpleBoard Mambo Component <= 1.0.1, allowing arbitrary file upload via image_upload.php. It bypasses a prior patch and checks for open_basedir restrictions.

Description

Unrestricted file upload vulnerability in image_upload.php in the SimpleBoard (com_simpleboard) component 1.0.1 and earlier for Mambo allows remote attackers to execute arbitrary code by uploading a file with an executable extension and an image/jpeg content type, then accessing this file via a direct request to the file in components/com_simpleboard/, a different vulnerability than CVE-2006-3528.

Exploits (1)

exploitdb WORKING POC VERIFIED
by t0pP8uZz · perlwebappsphp
https://www.exploit-db.com/exploits/6868

This exploit targets a file upload vulnerability in SimpleBoard Mambo Component <= 1.0.1, allowing arbitrary file upload via image_upload.php. It bypasses a prior patch and checks for open_basedir restrictions.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: SimpleBoard Mambo Component <= 1.0.1
No auth needed
Prerequisites: Perl environment with LWP::UserAgent and HTTP::Request::Common modules · Network access to the target · Target running vulnerable SimpleBoard Mambo Component
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/46223
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31981
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6868

Scores

EPSS 0.0333
EPSS Percentile 87.0%

Details

CWE
CWE-20
Status published
Products (5)
jan_de_graaff/com_simpleboard 0.9
jan_de_graaff/com_simpleboard 0.9.1
jan_de_graaff/com_simpleboard 0.9.2
jan_de_graaff/com_simpleboard 1.0 rc1 (3 CPE variants)
jan_de_graaff/com_simpleboard < 1.0.1
Published May 28, 2009
Tracked Since Feb 18, 2026