CVE-2008-6956
mxCamArchive 2.2 - Authenticated PHP Code Injection via Description Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6956. PoCs published by ahmadbady.
AI-analyzed exploit summary This exploit leverages a file inclusion vulnerability in mxcamarchive 2.2 to achieve remote code execution by injecting PHP code into the web cam description field, which is then executed via a crafted HTTP request.
Description
Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to inject arbitrary PHP code into an unspecified program via the description parameter, which is executed by invocation of index.php. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit leverages a file inclusion vulnerability in mxcamarchive 2.2 to achieve remote code execution by injecting PHP code into the web cam description field, which is then executed via a crafted HTTP request.