CVE-2010-0390
PHP F1 Max's Image Uploader 1.0 - Unauthenticated Arbitrary File Upload via pjpeg/jpeg Extension Handling
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-0390. PoCs published by indoushka.
AI-analyzed exploit summary This exploit demonstrates a shell upload vulnerability in Max's Image Uploader (PHP F1). The attacker can upload a malicious PHP file and execute it by accessing the uploaded file in the 'original' directory.
Description
Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max's Image Uploader 1.0, when Apache is not configured to handle the mime-type for files with pjpeg or jpeg extensions, allows remote attackers to execute arbitrary code by uploading a file with a pjpeg or jpeg extension, then accessing it via a direct request to the file in original/. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates a shell upload vulnerability in Max's Image Uploader (PHP F1). The attacker can upload a malicious PHP file and execute it by accessing the uploaded file in the 'original' directory.