6.8
CVSSv2

CVE-2008-7123

Published: 31/08/2009 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Static code injection vulnerability in admin/configuration/modifier.php in zKup CMS 2.0 up to and including 2.3 allows remote malicious users to inject arbitrary PHP code into fichiers/config.php via a null byte (%00) in the login parameter in an ajout action, which bypasses the regular expression check.

Vulnerable Product Search on Vulmon Subscribe to Product

zkup zkup 2.0

zkup zkup 2.01

zkup zkup 2.02

zkup zkup 2.03

Exploits

#!/usr/bin/php <?php /* * Name: zKup CMS v20 <= v23 0-day exploit (upload) * Credits: Charles "real" F <charlesfol[at]hotmailfr> * Date: 03-08-2008 * Conditions: PHP Version, magic_quotes_gpc=Off * * This exploit spawn a php uploader in your victim's * server * * Okay, you may need explanations: * * First, we can u ...