A file upload restriction bypass vulnerability exists in Pluck CMS versions prior to 4.7.13. The vulnerability allows an authenticated admin user to bypass file upload restrictions via the 'manage files' functionality. This can be exploited to upload arbitrary files, including those that can lead to remote code execution on the host system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a Python 3 proof-of-concept exploit for CVE-2020-29607 affecting Pluck CMS <= 4.7.13. Structure is minimal: (1) CVE-2020-29607.py is the main exploit script; (2) README.md documents setup and usage. Exploit flow: it creates a requests.Session, performs an authenticated login to /login.php using the supplied admin password, then uploads a PHP webshell disguised as a .phar file to the admin file manager endpoint /admin.php?action=files. Because the file manager does not properly validate extensions and Apache/PHP may execute .phar as PHP, the uploaded file becomes an executable webshell at /files/shell.phar. The script verifies RCE by running the command 'id' through the webshell (via GET parameter cmd) and then provides an interactive command loop using prompt_toolkit. Primary capability is authenticated remote code execution as the web server user through a persistent uploaded webshell. No additional post-exploitation modules (reverse shell, privilege escalation, cleanup) are included; the payload is hardcoded and basic, making the PoC operational but not highly modular.
This repository contains a Python 3 exploit script (pluck_exploit.py) and a README.md file. The exploit targets Pluck CMS version 4.7.13, specifically exploiting CVE-2020-29607, a file upload restriction bypass vulnerability. The script authenticates as an admin user, uploads a minimal PHP webshell (shell.phar) via the vulnerable file manager, and provides the attacker with a direct URL to execute arbitrary system commands on the target server. The exploit requires valid admin credentials and network access to the target CMS instance. The payload is a simple PHP webshell, and the attack is performed over HTTP. The repository is structured simply, with the exploit logic contained in a single Python file and comprehensive usage instructions in the README.
This repository contains an exploit for CVE-2020-29607, a file upload restriction bypass vulnerability in Pluck CMS version 4.7.13 and earlier. The exploit is implemented in a single Python script (exploit.py) that automates the process of authenticating to the CMS as an admin, uploading a PHP webshell (based on p0wny-shell) via the vulnerable file upload functionality, and providing the attacker with a remote shell on the target server. The exploit requires valid admin credentials and the path to the Pluck CMS installation. The README.md provides a clear description of the vulnerability, usage instructions, and references to the CVE and ExploitDB entries. The main attack vector is network-based, targeting the HTTP interface of the CMS. The endpoints involved include the login page, the file upload handler, and the location where the webshell is deployed. The payload is a PHP webshell that allows for arbitrary command execution, file download, and directory navigation. The repository is well-structured, with a clear separation between documentation and exploit code.
This repository contains a Python exploit script (myexploit_CVE.py) and a README.txt. The exploit targets a file upload restriction bypass vulnerability in Pluck CMS versions prior to 4.7.13. The script authenticates to the CMS admin interface using provided credentials, then uploads a PHP webshell (shell.phar) via the vulnerable file upload functionality. Upon successful upload, the shell can be accessed via a predictable URL and provides an interactive command execution interface branded as 'alien@shell'. The exploit requires Python 3 and the requests module. The README provides detailed usage instructions, parameters, and notes on modifications. The main attack vector is network-based, targeting the web admin interface of Pluck CMS. The endpoints involved include the login page, file upload handler, and the final webshell location. The repository is operational, providing a working exploit and payload, but is not part of a larger framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.