CVE-2008-7124

zKup CMS 2.0-2.3 - Unauthenticated Privilege Escalation via Direct Admin Configuration Access

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2008-7124. PoCs published by Charles Fol.

AI-analyzed exploit summary This exploit adds an admin user to zKup CMS versions 2.0 to 2.3 by sending a crafted POST request to the admin configuration page. It bypasses authentication by directly submitting user credentials and privilege level to the vulnerable endpoint.

Description

zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allows remote attackers to gain administrator privileges via a direct request, as demonstrated by adding a new administrator.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Charles Fol · phpwebappsphp
https://www.exploit-db.com/exploits/5219

This exploit adds an admin user to zKup CMS versions 2.0 to 2.3 by sending a crafted POST request to the admin configuration page. It bypasses authentication by directly submitting user credentials and privilege level to the vulnerable endpoint.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: zKup CMS v2.0 to v2.3
No auth needed
Prerequisites: Target URL · Desired admin username · Desired admin password
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Charles Fol · phpwebappsphp
https://www.exploit-db.com/exploits/5220

This exploit leverages a NULL byte injection vulnerability in zKup CMS v2.0 to v2.3 to bypass input validation and inject malicious PHP code into the configuration file, resulting in arbitrary file upload functionality. The exploit requires magic_quotes_gpc to be off and targets the admin configuration modifier script.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: zKup CMS v2.0 <= v2.3
No auth needed
Prerequisites: PHP with magic_quotes_gpc=Off · Access to the admin configuration modifier script
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/43081
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5220
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29276
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28149
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5219
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41068

Scores

EPSS 0.0861
EPSS Percentile 94.4%

Details

CWE
CWE-287
Status published
Products (4)
zkup/zkup 2.0
zkup/zkup 2.01
zkup/zkup 2.02
zkup/zkup 2.03
Published Aug 31, 2009
Tracked Since Feb 18, 2026