CVE-2023-0455
HIGHbumsys < 1.0.3-beta - Unrestricted Upload of File with Dangerous Type
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-0455. PoCs published by AFFAN AHMED.
AI-analyzed exploit summary This exploit demonstrates an unrestricted file upload vulnerability in unilogies/bumsys v1.0.3-beta, allowing an attacker to upload a malicious PHP file disguised as an image, leading to remote code execution (RCE). The PoC includes a Burp Suite request showing the upload of a PHP file with embedded system command execution.
Description
Unrestricted Upload of File with Dangerous Type in GitHub repository unilogies/bumsys prior to v1.0.3-beta.
Exploits (1)
This exploit demonstrates an unrestricted file upload vulnerability in unilogies/bumsys v1.0.3-beta, allowing an attacker to upload a malicious PHP file disguised as an image, leading to remote code execution (RCE). The PoC includes a Burp Suite request showing the upload of a PHP file with embedded system command execution.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H