CVE-2009-1659
eLitius 1.0 - Unauthenticated Arbitrary File Upload via Avatar Content-Type Bypass
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1659. PoCs published by G4N0K.
AI-analyzed exploit summary This exploit leverages an arbitrary file upload vulnerability in eLitius v1.0 by spoofing the MIME type to upload a malicious PHP file, enabling remote command execution. It bypasses authentication and provides an interactive shell.
Description
Unrestricted file upload vulnerability in admin/uploadimage.php in eLitius 1.0 allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files via an avatar file with an accepted Content-Type such as image/gif, then requesting the file in admin/banners/.
Exploits (1)
This exploit leverages an arbitrary file upload vulnerability in eLitius v1.0 by spoofing the MIME type to upload a malicious PHP file, enabling remote command execution. It bypasses authentication and provides an interactive shell.