CVE-2020-36942
HIGHVictor CMS 1.0 - Authenticated Arbitrary File Upload via Profile Image Feature
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-36942. PoCs published by Mosaaed.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in Victor CMS 1.0, allowing authenticated users to upload a PHP shell and achieve remote code execution (RCE). The steps involve registering, logging in, uploading a malicious PHP file via the profile update feature, and accessing the shell in the img directory.
Description
Victor CMS 1.0 contains a file upload vulnerability that allows authenticated users to upload malicious PHP files through the profile image upload feature. Attackers can upload a PHP shell to the /img directory and execute system commands by accessing the uploaded file via web browser.
Exploits (1)
This exploit demonstrates an arbitrary file upload vulnerability in Victor CMS 1.0, allowing authenticated users to upload a PHP shell and achieve remote code execution (RCE). The steps involve registering, logging in, uploading a malicious PHP file via the profile update feature, and accessing the shell in the img directory.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H