CVE-2008-6943
ScriptsFeed Recipes Listing Portal - Authenticated Remote Code Execution via Recipe Photo Upload
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2008-6943. PoCs published by ZoRLu.
AI-analyzed exploit summary This exploit demonstrates a remote file upload vulnerability in ScriptsFeed Recipes Listing Portal, allowing an authenticated attacker to upload a malicious PHP shell by manipulating the recipe photo upload functionality. The attacker can then execute arbitrary commands on the server by accessing the uploaded shell.
Description
Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a recipe photo, then accessing it via a direct request to the file in pictures/.
Exploits (3)
This exploit demonstrates a remote file upload vulnerability in ScriptsFeed Recipes Listing Portal, allowing an authenticated attacker to upload a malicious PHP shell by manipulating the recipe photo upload functionality. The attacker can then execute arbitrary commands on the server by accessing the uploaded shell.
This exploit demonstrates a remote file upload vulnerability in ScriptsFeed Real Estate Classifieds Software, allowing an attacker to upload a malicious PHP shell by exploiting the profile image upload functionality. The exploit requires authentication and leverages the software's handling of user-uploaded images to achieve remote code execution.
This exploit demonstrates a remote file upload vulnerability in ScriptsFeed Auto Classifieds Software, allowing an attacker to upload a malicious PHP shell by exploiting the profile image upload functionality. The attacker can then execute arbitrary code by accessing the uploaded shell via a predictable path.