CVE-2013-2267
HIGHFUDforum 3.0.4 - Remote Code Execution via PHP Code Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-2267. PoCs published by High-Tech Bridge.
AI-analyzed exploit summary This exploit leverages a PHP code injection vulnerability in FUDforum's admreplace.php by manipulating the regex_str and regex_with parameters to execute arbitrary PHP code (e.g., phpinfo()). The attack requires an authenticated session and exploits insufficient input sanitization.
Description
PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the system.
Exploits (1)
This exploit leverages a PHP code injection vulnerability in FUDforum's admreplace.php by manipulating the regex_str and regex_with parameters to execute arbitrary PHP code (e.g., phpinfo()). The attack requires an authenticated session and exploits insufficient input sanitization.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H