CVE-2015-1371
ferretCMS 1.0.4-alpha - Authenticated Remote Code Execution via Unrestricted File Upload
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-1371.
AI-analyzed exploit summary This advisory details multiple vulnerabilities in ferretCMS v1.0.4-alpha, including stored/reflected XSS, SQL injection, and arbitrary file upload. It provides specific URLs and payloads for exploitation but does not include functional exploit code.
Description
Unrestricted file upload vulnerability in ferretCMS 1.0.4-alpha allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in custom/uploads/.
Exploits (1)
This advisory details multiple vulnerabilities in ferretCMS v1.0.4-alpha, including stored/reflected XSS, SQL injection, and arbitrary file upload. It provides specific URLs and payloads for exploitation but does not include functional exploit code.