CVE-2012-10052
CRITICALEGallery 1.2 - Unauthenticated Arbitrary File Upload via uploadify.php
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2012-10052.
PoCs published by Metasploit, Sammy FORGIT, juan vazquez, including Metasploit module exploits/unix/webapp/egallery_upload_exec.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated file upload vulnerability in EGallery 1.2 via the uploadify.php endpoint, allowing arbitrary PHP code execution. It uploads a malicious PHP payload and triggers it via HTTP GET request.
Description
EGallery version 1.2 contains an unauthenticated arbitrary file upload vulnerability in the uploadify.php script. The application fails to validate file types or enforce authentication, allowing remote attackers to upload malicious PHP files directly into the web-accessible egallery/ directory. This results in full remote code execution under the web server context.
Exploits (2)
This Metasploit module exploits an unauthenticated file upload vulnerability in EGallery 1.2 via the uploadify.php endpoint, allowing arbitrary PHP code execution. It uploads a malicious PHP payload and triggers it via HTTP GET request.
This Metasploit module exploits an unauthenticated file upload vulnerability in EGallery 1.2 via uploadify.php, allowing arbitrary PHP code execution. It uploads a malicious PHP payload and triggers it via HTTP request.
References (5)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N