pPIM 1.0 - Upload/Change Password

Author: Stack
type: webapps
platform: php
port: 
date_added: 2008-08-10  
date_updated: 2016-12-30  
verified: 1  
codes: OSVDB-47630;CVE-2008-4528;OSVDB-47629;CVE-2008-4428;CVE-2008-4427;CVE-2008-4426;CVE-2008-4425  
tags:   
aliases:   
screenshot_url:   
application_url: http://www.exploit-db.comppim.zip  

raw file: 6231.txt  
Ppim <= 1.0 (upload/change password) Multiple Vulnerabilities
cript : Ppim v1.0
Download : http://scripts.ringsworld.com/organizers/ppim.zip
By Stack
Poc 1: change password
for change password go to this link
http://localhost/ppim/changepassword.php
writhe your password and confirm it

Poc 2 : upload
http://localhost/ppim/upload.php
you can upload you php shell in this link
after you go here
http://localhost/ppim/shell.php

# milw0rm.com [2008-08-11]