CVE-2012-10050
CRITICALCuteFlow < 2.11.2 - Unauthenticated Arbitrary File Upload via restart_circulation_values_write.php
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2012-10050.
PoCs published by Metasploit, bcoles, including Metasploit module exploits/multi/http/cuteflow_upload_exec.
AI-analyzed exploit summary This Metasploit module exploits an arbitrary file upload vulnerability in CuteFlow v2.11.2, allowing unauthenticated attackers to upload and execute PHP payloads. The exploit leverages a multipart form upload to place a malicious PHP file in the 'upload/___1/' directory and then triggers its execution.
Description
CuteFlow version 2.11.2 and earlier contains an arbitrary file upload vulnerability in the restart_circulation_values_write.php script. The application fails to validate or restrict uploaded file types, allowing unauthenticated attackers to upload arbitrary PHP files to the upload/___1/ directory. These files are then accessible via the web server, enabling remote code execution.
Exploits (2)
This Metasploit module exploits an arbitrary file upload vulnerability in CuteFlow v2.11.2, allowing unauthenticated attackers to upload and execute PHP payloads. The exploit leverages a multipart form upload to place a malicious PHP file in the 'upload/___1/' directory and then triggers its execution.
This Metasploit module exploits an arbitrary file upload vulnerability in CuteFlow v2.11.2, allowing unauthenticated attackers to upload and execute PHP payloads via the 'upload/___1/' directory.
References (6)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N