CVE-2023-37165
CRITICALMillhouse-Project 1.414 - Remote Code Execution via /add_post_sql.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-37165. PoCs published by Chokri Hammedi.
AI-analyzed exploit summary This exploit targets a file upload vulnerability in Millhouse-Project 1.414, allowing remote code execution by uploading a malicious PHP file disguised as an image. The exploit sends a multipart form request to upload the file and then executes arbitrary commands via the uploaded shell.
Description
Millhouse-Project v1.414 was discovered to contain a remote code execution (RCE) vulnerability via the component /add_post_sql.php.
Exploits (1)
This exploit targets a file upload vulnerability in Millhouse-Project 1.414, allowing remote code execution by uploading a malicious PHP file disguised as an image. The exploit sends a multipart form request to upload the file and then executes arbitrary commands via the uploaded shell.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H