github.com
https://github.com/moziloDasEinsteigerCMS/mozilo3.0 CVE-2024-44871
HIGH
MoziloCMS 3.0 - Remote Code Execution (RCE)
Record summary
CVE-2024-44871 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via uploading a crafted file.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
mozilocmsBrowse mozilo / mozilocmsDefault status: unknown | CVE List | 3.0 | affected |
Proofs of concept
2Catalogued exploits
ExploitDBMoziloCMS 3.0 - Remote Code Execution (RCE)ExploitDB exploitby Olakojo Olaoluwa JoshuaNot analyzed1 file
Repository PoCs
GitHubvances25/CVE-2024-44871Repository PoCby vances25Stars: 0Not analyzed3 files
References
3github.com
https://github.com/sec-fortress/Exploits/tree/main/CVE-2024-44871 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-44871