CVE-2018-16370
CRITICALPESCMS Team 2.2.1 - Unauthenticated Arbitrary PHP File Upload via ZIP Archive
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-16370. PoCs published by snappyJack.
AI-analyzed exploit summary This repository contains a writeup describing CVE-2018-16370, an arbitrary PHP code execution vulnerability in PESCMS Team 2.2.1. The vulnerability allows attackers to upload and execute arbitrary PHP code via a ZIP archive through the /Public/?g=Team&m=Setting&a=upgrade endpoint.
Description
In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&m=Setting&a=upgrade by placing a .php file in a ZIP archive.
Exploits (1)
This repository contains a writeup describing CVE-2018-16370, an arbitrary PHP code execution vulnerability in PESCMS Team 2.2.1. The vulnerability allows attackers to upload and execute arbitrary PHP code via a ZIP archive through the /Public/?g=Team&m=Setting&a=upgrade endpoint.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H