PhpCollab < 2.5.1 - Authenticated Arbitrary File Upload via Client Logo Upload
Title source: llmExploitation Summary
CVE-2017-6090 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 4 public exploits from researchers including Metasploit, Sysdream, jlk, including a Metasploit module exploits/unix/webapp/phpcollab_upload_exec.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated file upload vulnerability in phpCollab 2.5.1, allowing arbitrary PHP code execution under the context of the web server user. It uploads a malicious PHP file via a multipart form request and triggers it to achieve RCE.
Description
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in logos_clients/.
Exploits (4)
This Metasploit module exploits an unauthenticated file upload vulnerability in phpCollab 2.5.1, allowing arbitrary PHP code execution under the context of the web server user. It uploads a malicious PHP file via a multipart form request and triggers it to achieve RCE.
This exploit demonstrates an unauthenticated arbitrary file upload vulnerability in PhpCollab 2.5.1, allowing an attacker to upload and execute malicious PHP files via a crafted HTTP POST request. The vulnerable code fails to properly filter file extensions, enabling remote code execution.
This repository provides a containerized environment for PhpCollab 2.5.1, which is vulnerable to CVE-2017-6090, a remote code execution vulnerability. It includes instructions for setting up the environment and exploiting the vulnerability using Metasploit.
This Metasploit module exploits an unauthenticated file upload vulnerability in phpCollab 2.5.1, allowing arbitrary PHP code execution via a malicious file upload to the 'logos_clients' directory.
Nuclei Templates (1)
http.title:"PhpCollab" || http.title:"phpcollab"
title="phpcollab"
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H