CVE-2020-37073
HIGHVictor CMS 1.0 - Authenticated Arbitrary File Upload via user_image Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-37073. PoCs published by Kishan Lal Choudhary.
AI-analyzed exploit summary This exploit demonstrates an authenticated arbitrary file upload vulnerability in Victor CMS 1.0, allowing an attacker to upload a malicious PHP file and execute system commands via a crafted request.
Description
Victor CMS 1.0 contains an authenticated file upload vulnerability that allows administrators to upload PHP files with arbitrary content through the user_image parameter. Attackers can upload a malicious PHP shell to the /img/ directory and execute system commands by accessing the uploaded file with a 'cmd' parameter.
Exploits (1)
This exploit demonstrates an authenticated arbitrary file upload vulnerability in Victor CMS 1.0, allowing an attacker to upload a malicious PHP file and execute system commands via a crafted request.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H