CVE-2008-6920
phpEmployment 1.8 - Unauthenticated Arbitrary File Upload via auth.php regnew Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6920. PoCs published by ahmadbady.
AI-analyzed exploit summary This exploit leverages an arbitrary file upload vulnerability in phpEmployment to achieve remote code execution by uploading a shell to the 'photoes' directory. The vulnerability is triggered via a specific URL path during user registration.
Description
Unrestricted file upload vulnerability in auth.php in phpEmployment 1.8 allows remote attackers to execute arbitrary code by uploading a file with an executable extension during a regnew action, then accessing it via a direct request to the file in photoes/.
Exploits (1)
This exploit leverages an arbitrary file upload vulnerability in phpEmployment to achieve remote code execution by uploading a shell to the 'photoes' directory. The vulnerability is triggered via a specific URL path during user registration.