Exploitation Summary
EIP tracks 1 public exploit for CVE-2023-53868. PoCs published by Mirabbas Ağalarov.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in Coppermine Gallery 1.6.25, allowing authenticated users to upload a malicious PHP file via a ZIP archive and achieve remote code execution.
Description
Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can upload a zipped PHP file with system commands to the plugin directory and execute arbitrary code by accessing the uploaded plugin script.
Exploits (1)
This exploit demonstrates an arbitrary file upload vulnerability in Coppermine Gallery 1.6.25, allowing authenticated users to upload a malicious PHP file via a ZIP archive and achieve remote code execution.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H