Exploitation Summary
EIP tracks 1 public exploit for CVE-2023-53883. PoCs published by Mirabbas Ağalarov.
AI-analyzed exploit summary This exploit demonstrates a Remote Code Execution (RCE) vulnerability in Webedition CMS v2.9.8.8 by injecting PHP code into the 'Description' field of a new page, which is then executed by the server.
Description
Webedition CMS v2.9.8.8 contains a remote code execution vulnerability that allows authenticated attackers to inject system commands through PHP page creation. Attackers can create a new PHP page with malicious system commands in the description field to execute arbitrary commands on the server.
Exploits (1)
This exploit demonstrates a Remote Code Execution (RCE) vulnerability in Webedition CMS v2.9.8.8 by injecting PHP code into the 'Description' field of a new page, which is then executed by the server.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H