Exploitation Summary
EIP tracks 2 public exploits for CVE-2011-3833.
PoCs published by Metasploit, Secunia Research, juan vazquez, including Metasploit module exploits/multi/http/sit_file_upload.
AI-analyzed exploit summary This Metasploit module exploits CVE-2011-3833 in Support Incident Tracker (SiT) <= 3.65 by combining two vulnerabilities: arbitrary file upload and directory path disclosure. It authenticates, retrieves the upload directory, uploads a malicious PHP file, and executes it to achieve remote code execution.
Description
Unrestricted file upload vulnerability in ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in an unspecified directory.
Exploits (2)
This Metasploit module exploits CVE-2011-3833 in Support Incident Tracker (SiT) <= 3.65 by combining two vulnerabilities: arbitrary file upload and directory path disclosure. It authenticates, retrieves the upload directory, uploads a malicious PHP file, and executes it to achieve remote code execution.
This Metasploit module exploits CVE-2011-3833 in Support Incident Tracker (SiT) by combining two vulnerabilities: arbitrary file upload and directory path disclosure. It authenticates, retrieves the upload directory, uploads a malicious PHP file, and executes it to achieve remote command execution.