Exploitation Summary
EIP tracks 2 public exploits for CVE-2012-10036.
PoCs published by Metasploit, BlackHawk, sinn3r, including Metasploit module exploits/unix/webapp/projectpier_upload_exec.
AI-analyzed exploit summary This Metasploit module exploits an arbitrary file upload vulnerability in Project Pier 0.8.8, allowing unauthenticated remote code execution by uploading a malicious PHP file and executing it. It supports both PHP and Linux x86 payloads.
Description
Project Pier 0.8.8 and earlier contains an unauthenticated arbitrary file upload vulnerability in tools/upload_file.php. The upload handler fails to validate the file type or enforce authentication, allowing remote attackers to upload malicious PHP files directly into a web-accessible directory. The uploaded file is stored with a predictable suffix and can be executed by requesting its URL, resulting in remote code execution.
Exploits (2)
This Metasploit module exploits an arbitrary file upload vulnerability in Project Pier 0.8.8, allowing unauthenticated remote code execution by uploading a malicious PHP file and executing it. It supports both PHP and Linux x86 payloads.
This Metasploit module exploits an unauthenticated arbitrary file upload vulnerability in Project Pier 0.8.0-0.8.8, allowing remote code execution by uploading a malicious PHP file and executing it via a crafted request.
References (6)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N