CVE-2008-6913
Zeeways ZEEJOBSITE 2.0 - Authenticated Arbitrary File Upload via Profile Photo
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6913. PoCs published by ZoRLu.
AI-analyzed exploit summary This exploit demonstrates a remote file upload vulnerability in ZEEJOBSITE v2.0, allowing attackers to upload a malicious PHP shell disguised as a GIF image. The shell is executed by accessing the uploaded file via a direct URL.
Description
Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a photo in a profile edit action, then accessing the file via a direct request to jobseekers/logos/.
Exploits (1)
This exploit demonstrates a remote file upload vulnerability in ZEEJOBSITE v2.0, allowing attackers to upload a malicious PHP shell disguised as a GIF image. The shell is executed by accessing the uploaded file via a direct URL.