CVE-2015-8358
bitrix.mpbuilder < 1.0.11 - Authenticated Path Traversal via Work Array Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-8358. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary This exploit demonstrates a PHP file inclusion vulnerability in bitrix.mpbuilder Bitrix module, allowing arbitrary file inclusion and execution via the 'work[]' POST parameter. It includes PoC forms for both direct file inclusion and session file-based command execution.
Description
Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the element name of the "work" array parameter to admin/bitrix.mpbuilder_step2.php.
Exploits (1)
This exploit demonstrates a PHP file inclusion vulnerability in bitrix.mpbuilder Bitrix module, allowing arbitrary file inclusion and execution via the 'work[]' POST parameter. It includes PoC forms for both direct file inclusion and session file-based command execution.