CVE-2009-1314
Web File Explorer 3.1 - Remote Code Execution via File Parameter in savefile Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1314. PoCs published by Osirys.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in WebFileExplorer 3.1, allowing authentication bypass via a crafted login request. It also shows how an attacker can upload arbitrary files (e.g., PHP shells) post-authentication, leading to remote command execution.
Description
body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the savefile action with a file parameter containing a filename that has an executable extension.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in WebFileExplorer 3.1, allowing authentication bypass via a crafted login request. It also shows how an attacker can upload arbitrary files (e.g., PHP shells) post-authentication, leading to remote command execution.