Exploitation Summary
EIP tracks 1 public exploit for CVE-2021-47888. PoCs published by Ricardo Ruiz.
AI-analyzed exploit summary This exploit targets an authenticated RCE vulnerability in Textpattern CMS versions prior to 4.8.3. It uploads a malicious PHP file via the file upload functionality and executes arbitrary commands through a crafted request.
Description
Textpattern versions prior to 4.8.3 contain an authenticated remote code execution vulnerability that allows logged-in users to upload malicious PHP files. Attackers can upload a PHP file with a shell command execution payload and execute arbitrary commands by accessing the uploaded file through a specific URL parameter.
Exploits (1)
This exploit targets an authenticated RCE vulnerability in Textpattern CMS versions prior to 4.8.3. It uploads a malicious PHP file via the file upload functionality and executes arbitrary commands through a crafted request.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H