CVE-2008-7052
Pre Real Estate Listings - Authenticated Arbitrary File Upload via Profile Logo
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-7052. PoCs published by BackDoor.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass via SQL injection in the login form and an unrestricted file upload vulnerability in the profile editing functionality of Pre Real Estate Listings. The SQL injection allows bypassing authentication, and the file upload can be abused to achieve remote code execution.
Description
Unrestricted file upload vulnerability in profile.php in Pre Projects Pre Real Estate Listings allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in re_images/.
Exploits (1)
This exploit demonstrates an authentication bypass via SQL injection in the login form and an unrestricted file upload vulnerability in the profile editing functionality of Pre Real Estate Listings. The SQL injection allows bypassing authentication, and the file upload can be abused to achieve remote code execution.