This exploit targets SkaDate Lite 2.0, leveraging an authenticated file upload vulnerability to achieve remote code execution by bypassing .htaccess restrictions via a .php5 extension. It uploads a malicious PHP script that creates a backdoor for command execution.
Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target:SkaDate Lite 2.0 (build 7651)
Auth required
Prerequisites:Valid admin credentials · Access to the admin panel