CVE-2010-0757
WikyBlog 1.7.3rc2 - Authenticated Remote Code Execution via Unrestricted File Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-0757. PoCs published by indoushka.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in WikyBlog 1.7.3rc2, including XSS, session fixation, and RFI. It provides specific attack vectors and payloads for each vulnerability.
Description
Unrestricted file upload vulnerability in index.php/Attach in WikyBlog 1.7.3rc2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension using the uploadform action, then accessing it via a direct request to the file in userfiles/[username]/uploaded/.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in WikyBlog 1.7.3rc2, including XSS, session fixation, and RFI. It provides specific attack vectors and payloads for each vulnerability.