CVE-2015-1587

Maarch GEC/GED < 1.4 and LetterBox < 2.8 - Unauthenticated Arbitrary File Upload via file_to_index.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2015-1587. PoCs published by Adrien Thierry, rastating, including Metasploit module exploits/unix/webapp/maarch_letterbox_file_upload.

AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in Maarch Letterbox <= 2.4 and Maarch GEC/GED <= 1.4. It uploads a backdoor PHP file via an unauthenticated endpoint, allowing remote code execution.

Description

Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earlier allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a request to a predictable filename in tmp/.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Adrien Thierry · phpwebappsphp
https://www.exploit-db.com/exploits/35113

This exploit demonstrates an arbitrary file upload vulnerability in Maarch Letterbox <= 2.4 and Maarch GEC/GED <= 1.4. It uploads a backdoor PHP file via an unauthenticated endpoint, allowing remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Maarch Letterbox <= 2.4, Maarch GEC/GED <= 1.4
No auth needed
Prerequisites: Access to the target URL · A PHP file to upload as a backdoor
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by rastating · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/maarch_letterbox_file_upload.rb

This Metasploit module exploits an unauthenticated file upload vulnerability in Maarch LetterBox 2.8, allowing arbitrary PHP file upload and remote code execution via the file_to_index.php script.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Maarch LetterBox 2.8
No auth needed
Prerequisites: Network access to the target · Maarch LetterBox 2.8 installation
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/35113
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/show/osvdb/113928

Scores

EPSS 0.4419
EPSS Percentile 98.6%

Details

Status published
Products (2)
maarch/gec\/ged < 1.4
maarch/letterbox < 2.8
Published Feb 19, 2015
Tracked Since Feb 18, 2026