CVE-2009-1615
Leap CMS 0.1.4 - Unauthenticated Arbitrary File Upload and Remote Code Execution via Manage Files
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1615. PoCs published by YEnH4ckEr.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in Leap CMS 0.1.4, including SQL injection for authentication bypass, XSS for cookie stealing, and shell upload. The PoC provides clear steps and payloads for each vulnerability.
Description
Unrestricted file upload vulnerability in Leap CMS 0.1.4 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via an admin.system.files (aka Manage Files) request to the default URI, then accessing the file via a direct request.
Exploits (1)
This exploit demonstrates multiple vulnerabilities in Leap CMS 0.1.4, including SQL injection for authentication bypass, XSS for cookie stealing, and shell upload. The PoC provides clear steps and payloads for each vulnerability.