CVE-2015-6967

Nibbleblog < 4.0.4 - Remote Code Execution via My Image Plugin File Upload

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 8 public exploits for CVE-2015-6967. PoCs published by Metasploit, flex0geek, dix0nym, including Metasploit module exploits/multi/http/nibbleblog_file_upload.

AI-analyzed exploit summary This Metasploit module exploits an authenticated file upload vulnerability in Nibbleblog 4.0.3, allowing arbitrary PHP code execution by uploading a malicious payload disguised as an image plugin.

Description

Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in content/private/plugins/my_image/image.php.

Exploits (8)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/38489

This Metasploit module exploits an authenticated file upload vulnerability in Nibbleblog 4.0.3, allowing arbitrary PHP code execution by uploading a malicious payload disguised as an image plugin.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Nibbleblog 4.0.3
Auth required
Prerequisites: Valid credentials for Nibbleblog admin panel · My Image plugin installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
github WORKING POC 20 stars
by flex0geek · cpoc
https://github.com/flex0geek/cves-exploits/tree/main/CVE-2015-6967

The repository contains a functional exploit for CVE-2015-6967, targeting Nibbleblog 4.0.3. The vulnerability arises from improper file extension handling in the 'My image' plugin, allowing arbitrary PHP file uploads leading to remote code execution (RCE).

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Nibbleblog 4.0.3
Auth required
Prerequisites: valid admin credentials · access to the admin dashboard
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec WORKING POC 15 stars
by dix0nym · poc
https://github.com/dix0nym/CVE-2015-6967

This repository contains a functional Python exploit for CVE-2015-6967, an arbitrary file upload vulnerability in Nibbleblog 4.0.3. The exploit authenticates, uploads a malicious PHP file via the 'my_image' plugin, and executes it to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Nibbleblog 4.0.3
Auth required
Prerequisites: Valid admin credentials · Network access to the target · PHP payload file
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by innocentx0 · poc
https://github.com/innocentx0/CVE-2015-6967-EXPLOIT

This Python script exploits CVE-2015-6967 in Nibbleblog by authenticating as an admin, uploading a PHP reverse shell via a vulnerable plugin configuration, and executing it to gain remote code execution. The exploit uses a standard reverse shell payload and leverages session management for authentication.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Nibbleblog (version not specified, but likely <= 4.0.3)
Auth required
Prerequisites: Valid admin credentials for Nibbleblog · Network access to the target · PHP execution environment on the target
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by cuerv0x · poc
https://github.com/cuerv0x/CVE-2015-6967

This repository contains a functional exploit for CVE-2015-6967, targeting Nibbleblog's file upload vulnerability to achieve remote code execution (RCE). The exploit authenticates as an admin, uploads a malicious PHP shell via the 'my_image' plugin, and includes a reverse shell payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Nibbleblog (version not specified, but likely <= 4.0.3)
Auth required
Prerequisites: Valid admin credentials · Network access to the target · Nibbleblog installed with vulnerable plugin
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by 3mpir3Albert · poc
https://github.com/3mpir3Albert/HTB_Nibbles

This repository contains functional exploit code for CVE-2015-6967, targeting Nibbleblog's arbitrary file upload vulnerability. The scripts demonstrate authentication bypass and remote code execution via malicious PHP file upload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Nibbleblog (version not specified)
Auth required
Prerequisites: Admin credentials · PHP reverse shell file · Listener on specified port
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by FredBrave · poc
https://github.com/FredBrave/CVE-2015-6967

This repository contains a functional Python exploit for CVE-2015-6967, targeting Nibbleblog 4.0.3. The exploit authenticates, uploads a malicious PHP shell via a plugin configuration vulnerability, and executes arbitrary commands.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Nibbleblog 4.0.3
Auth required
Prerequisites: Valid credentials for Nibbleblog admin panel · Network access to the target
devstral-2 · analyzed Feb 18, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Unknown, s name? · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/nibbleblog_file_upload.rb

This Metasploit module exploits an authenticated file upload vulnerability in Nibbleblog 4.0.3, allowing arbitrary PHP code execution by uploading a malicious payload disguised as an image file via the 'My Image' plugin.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Nibbleblog 4.0.3
Auth required
Prerequisites: Valid credentials for Nibbleblog admin panel · My Image plugin installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

EPSS 0.7525
EPSS Percentile 98.9%

Details

Status published
Products (1)
nibbleblog/nibbleblog < 4.0.4
Published Sep 16, 2015
Tracked Since Feb 18, 2026