CVE-2012-10052

CRITICAL

EGallery 1.2 - Unauthenticated Arbitrary File Upload via uploadify.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2012-10052. PoCs published by Metasploit, Sammy FORGIT, juan vazquez, including Metasploit module exploits/unix/webapp/egallery_upload_exec.

AI-analyzed exploit summary This Metasploit module exploits an unauthenticated file upload vulnerability in EGallery 1.2 via the uploadify.php endpoint, allowing arbitrary PHP code execution. It uploads a malicious PHP payload and triggers it via HTTP GET request.

Description

EGallery version 1.2 contains an unauthenticated arbitrary file upload vulnerability in the uploadify.php script. The application fails to validate file types or enforce authentication, allowing remote attackers to upload malicious PHP files directly into the web-accessible egallery/ directory. This results in full remote code execution under the web server context.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/20029

This Metasploit module exploits an unauthenticated file upload vulnerability in EGallery 1.2 via the uploadify.php endpoint, allowing arbitrary PHP code execution. It uploads a malicious PHP payload and triggers it via HTTP GET request.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: EGallery 1.2
No auth needed
Prerequisites: Network access to the target · EGallery 1.2 with exposed uploadify.php
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Sammy FORGIT, juan vazquez · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/egallery_upload_exec.rb

This Metasploit module exploits an unauthenticated file upload vulnerability in EGallery 1.2 via uploadify.php, allowing arbitrary PHP code execution. It uploads a malicious PHP payload and triggers it via HTTP request.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: EGallery 1.2
No auth needed
Prerequisites: Network access to the target · EGallery 1.2 with exposed uploadify.php
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v4 9.3
EPSS 0.0139
EPSS Percentile 68.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
EGallery/EGallery 1.2
Published Aug 08, 2025
Tracked Since Feb 18, 2026