CVE-2017-17593

HIGH

Simple Chatting System 1.0 - Arbitrary File Upload via my_profile.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-17593. PoCs published by Ihsan Sencan.

AI-analyzed exploit summary This is a writeup describing an arbitrary file upload vulnerability in Simple Chatting System 1.0. It provides URLs for exploitation but lacks actual exploit code or payload details.

Description

Simple Chatting System 1.0 allows Arbitrary File Upload via view/my_profile.php, which places files under uploads/.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/43237

This is a writeup describing an arbitrary file upload vulnerability in Simple Chatting System 1.0. It provides URLs for exploitation but lacks actual exploit code or payload details.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Simple Chatting System 1.0
No auth needed
Prerequisites: Access to the target application · Ability to upload files
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/43237/

Scores

CVSS v3 7.5
EPSS 0.0605
EPSS Percentile 92.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-434
Status published
Products (1)
simple_chatting_system_project/simple_chatting_system 1.0
Published Dec 13, 2017
Tracked Since Feb 18, 2026