CVE-2008-6944
ScriptsFeed Auto Classifieds - Authenticated Arbitrary File Upload via Profile Logo
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2008-6944. PoCs published by ZoRLu.
AI-analyzed exploit summary This exploit demonstrates a remote file upload vulnerability in ScriptsFeed Recipes Listing Portal, allowing an authenticated attacker to upload a malicious PHP shell by manipulating the recipe photo upload functionality. The attacker can then execute arbitrary commands on the server by accessing the uploaded shell.
Description
Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in cars_images/.
Exploits (3)
This exploit demonstrates a remote file upload vulnerability in ScriptsFeed Recipes Listing Portal, allowing an authenticated attacker to upload a malicious PHP shell by manipulating the recipe photo upload functionality. The attacker can then execute arbitrary commands on the server by accessing the uploaded shell.
This exploit demonstrates a remote file upload vulnerability in ScriptsFeed Real Estate Classifieds Software, allowing an attacker to upload a malicious PHP shell by exploiting the profile image upload functionality. The uploaded shell can then be accessed via a predictable path to achieve remote code execution.
This exploit demonstrates a remote file upload vulnerability in ScriptsFeed Auto Classifieds Software, allowing an attacker to upload a malicious PHP shell by exploiting the profile image upload functionality. The attacker can then execute arbitrary code by accessing the uploaded shell via a predictable path.