CVE-2013-0803
CRITICALPolarBear CMS 2.5 - Unauthenticated Arbitrary File Upload via upload.php
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2013-0803.
PoCs published by Metasploit, Fady Mohamed Osman, including Metasploit module exploits/multi/http/polarcms_upload_exec.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated file upload vulnerability in PolarPearCms via the upload.php script, allowing arbitrary PHP code execution. It uploads a malicious PHP payload to a writable directory and triggers execution via HTTP request.
Description
A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code.
Exploits (2)
This Metasploit module exploits an unauthenticated file upload vulnerability in PolarPearCms via the upload.php script, allowing arbitrary PHP code execution. It uploads a malicious PHP payload to a writable directory and triggers execution via HTTP request.
This Metasploit module exploits an unauthenticated file upload vulnerability in PolarBear CMS, allowing arbitrary PHP code execution by uploading a malicious file to a writable directory and triggering it via HTTP request.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H