CVE-2012-10037
CRITICALPhpTax 0.8 - Unauthenticated Remote Code Execution via drawimage.php pfilez Parameter
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2012-10037.
PoCs published by Metasploit, Jean Pascal Pereira, including Metasploit module exploits/multi/http/phptax_exec.
AI-analyzed exploit summary This Metasploit module exploits a command injection vulnerability in PhpTax 0.8 via the 'pfilez' parameter in drawimage.php, allowing arbitrary remote code execution under the context of the web server. The exploit sends a crafted GET request with the payload embedded in the 'pfilez' parameter.
Description
PhpTax version 0.8 contains a remote code execution vulnerability in drawimage.php. The pfilez GET parameter is unsafely passed to the exec() function without sanitization. A remote attacker can inject arbitrary shell commands, leading to code execution under the web server's context. No authentication is required.
Exploits (3)
This Metasploit module exploits a command injection vulnerability in PhpTax 0.8 via the 'pfilez' parameter in drawimage.php, allowing arbitrary remote code execution under the context of the web server. The exploit sends a crafted GET request with the payload embedded in the 'pfilez' parameter.
The exploit leverages a file inclusion vulnerability in phptax 0.8 via the `pfilez` parameter in `drawimage.php`, allowing remote code execution through command injection. The PoC demonstrates a bind shell using netcat.
This Metasploit module exploits a command injection vulnerability in PhpTax 0.8 via the 'pfilez' parameter in drawimage.php, allowing arbitrary code execution without authentication.
References (4)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N