code-projects.org
https://code-projects.org/artworks-gallery-in-php-css-javascript-and-mysql-free-download CVE-2020-28688
HIGH
Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Add Artwork
Record summary
CVE-2020-28688 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBArtworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Add ArtworkExploitDB exploitby Shahrukh Iqbal MirzaNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-28688 packetstormsecurity.com
https://packetstormsecurity.com/files/160095/Artworks-Gallery-1.0-Shell-Upload.html