CVE-2012-10026
CRITICALWordPress Plugin Asset-Manager < 2.0 - Unauthenticated Arbitrary File Upload via upload.php
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2012-10026.
PoCs published by Metasploit, Sammy FORGIT, including Metasploit module exploits/unix/webapp/wp_asset_manager_upload_exec.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated file upload vulnerability in the WordPress Asset-Manager plugin (<= 2.0) to achieve remote code execution by uploading a malicious PHP payload.
Description
The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary file upload vulnerability in upload.php. The endpoint fails to properly validate and restrict uploaded file types, allowing remote attackers to upload malicious PHP scripts to a predictable temporary directory. Once uploaded, the attacker can execute the file via a direct HTTP GET request, resulting in remote code execution under the web server’s context.
Exploits (3)
This Metasploit module exploits an unauthenticated file upload vulnerability in the WordPress Asset-Manager plugin (<= 2.0) to achieve remote code execution by uploading a malicious PHP payload.
This exploit demonstrates an arbitrary file upload vulnerability in the WordPress Asset Manager plugin (v0.2), allowing an attacker to upload a malicious PHP file (e.g., a web shell) via a cURL POST request to the vulnerable endpoint. The uploaded file can then be accessed to execute arbitrary PHP code.
This Metasploit module exploits an unauthenticated file upload vulnerability in WordPress Asset-Manager plugin <= 2.0, allowing arbitrary PHP code execution by uploading a malicious file to a temp directory and then executing it.
References (6)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H