CVE-2023-27040
CRITICALSimple Image Gallery Web App 1.0 - Remote Code Execution via Username Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-27040. PoCs published by Tagoletta.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated RCE vulnerability in Simple Image Gallery 1.0 by bypassing login via SQL injection and uploading a malicious PHP shell disguised as an image file. The payload allows command execution via a GET parameter.
Description
Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter.
Exploits (1)
This exploit demonstrates an unauthenticated RCE vulnerability in Simple Image Gallery 1.0 by bypassing login via SQL injection and uploading a malicious PHP shell disguised as an image file. The payload allows command execution via a GET parameter.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H