CVE-2023-39147
HIGHUvdesk 1.1.3 - Unauthenticated Arbitrary File Upload and Remote Code Execution via Image File
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-39147. PoCs published by Daniel Barros.
AI-analyzed exploit summary This exploit leverages an authenticated file upload vulnerability in Uvdesk v1.1.3 to achieve remote code execution by uploading a malicious PHP file disguised as an image. The exploit logs in with hardcoded credentials, uploads the file, and executes arbitrary commands via a GET parameter.
Description
An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.
Exploits (1)
This exploit leverages an authenticated file upload vulnerability in Uvdesk v1.1.3 to achieve remote code execution by uploading a malicious PHP file disguised as an image. The exploit logs in with hardcoded credentials, uploads the file, and executes arbitrary commands via a GET parameter.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H