CVE-2008-6914
Zeeproperty 1.0 - Authenticated Arbitrary File Upload via Profile Photo
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6914. PoCs published by ZoRLu.
AI-analyzed exploit summary The exploit demonstrates a file upload vulnerability in ZEEPROPERTY v1.0, allowing remote attackers to upload a malicious PHP shell disguised as a GIF image. It also includes an XSS vulnerability example.
Description
Unrestricted file upload vulnerability in viewprofile.php in Zeeways ZEEPROPERTY 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a photo in a profile modification, then accessing a related file via a direct request to the file in companylogo/.
Exploits (1)
The exploit demonstrates a file upload vulnerability in ZEEPROPERTY v1.0, allowing remote attackers to upload a malicious PHP shell disguised as a GIF image. It also includes an XSS vulnerability example.