Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2021-43258 — ChurchInfo 1.2.13-1.3.0 Remote Code Execution Exploit | Kitploit
Tools/GitHubGitHub/mrvirusir/cve-2021-43258
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRemote Access Tool
GitHubmrvirusir/cve-2021-43258

CVE-2021-43258

ChurchInfo 1.2.13-1.3.0 Remote Code Execution Exploit

View Repository
253 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2021-43258

ChurchInfo 1.2.13-1.3.0 Remote Code Execution Exploit

Full titleChurchInfo 1.2.13-1.3.0 Remote Code Execution Exploit
Date add21-11-2022
Categoryremote exploits
Platformphp
Risk[Security RiskCritical]
DescriptionThis Metasploit module exploits the logic in the CartView.php page when crafting a draft email with an attachment. By uploading an attachment for a draft email, the attachment will be placed in the /tmp_attach/ folder of the ChurchInfo web server, which is accessible over the web by any user. By uploading a PHP attachment and then browsing to the location of the uploaded PHP file on the web server, arbitrary code execution as the web daemon user (e.g. www-data) can be achieved.
CVECVE-2021-43258
Download Tool