CVE-2015-6567
HIGHWolf CMS < 0.8.3.1 - Authenticated Arbitrary File Upload and PHP Code Execution via File Manager
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2015-6567. PoCs published by s0nk3y, Narendra Bhati.
AI-analyzed exploit summary This Metasploit module exploits an arbitrary PHP file upload vulnerability in WolfCMS 0.8.2 by authenticating as an admin, bypassing CSRF protection, and uploading a malicious PHP payload to achieve remote code execution.
Description
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "filename" properly. Exploitation requires a registered user who has access to upload functionality.
Exploits (2)
This Metasploit module exploits an arbitrary PHP file upload vulnerability in WolfCMS 0.8.2 by authenticating as an admin, bypassing CSRF protection, and uploading a malicious PHP payload to achieve remote code execution.
This is a writeup describing an arbitrary file upload vulnerability in Wolf CMS 0.8.2, leading to remote command execution. It outlines the steps to exploit the vulnerability but does not include actual exploit code.
References (7)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H