CVE-2008-6942
ScriptsFeed Realtor Classifieds System - Authenticated Remote Code Execution via Profile Logo Upload
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2008-6942. PoCs published by ZoRLu.
AI-analyzed exploit summary This exploit demonstrates a remote file upload vulnerability in ScriptsFeed Real Estate Classifieds Software, allowing an attacker to upload a malicious PHP shell by exploiting the profile image upload functionality. The uploaded shell can then be accessed via a predictable path to achieve remote code execution.
Description
Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in re_images/.
Exploits (3)
This exploit demonstrates a remote file upload vulnerability in ScriptsFeed Real Estate Classifieds Software, allowing an attacker to upload a malicious PHP shell by exploiting the profile image upload functionality. The uploaded shell can then be accessed via a predictable path to achieve remote code execution.
This exploit demonstrates a remote file upload vulnerability in ScriptsFeed Recipes Listing Portal, allowing an attacker to upload a malicious PHP shell by leveraging the picture upload functionality in the recipe submission process. The attacker must register, log in, and submit a recipe with a malicious file disguised as a photo.
This exploit demonstrates a remote file upload vulnerability in ScriptsFeed Auto Classifieds Software, allowing an attacker to upload a malicious PHP shell by exploiting the profile image upload functionality. The attacker can then execute arbitrary code by accessing the uploaded shell via a predictable path.