CVE-2012-10056
HIGHPHP Volunteer Management System v1.0.2 - Code Injection
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2012-10056.
PoCs published by Metasploit, Ashoo, including Metasploit module exploits/multi/http/php_volunteer_upload_exec.
AI-analyzed exploit summary This Metasploit module exploits an arbitrary file upload vulnerability in PHP Volunteer Management System v1.0.2, allowing authenticated users to upload and execute malicious PHP payloads.
Description
PHP Volunteer Management System v1.0.2 contains an arbitrary file upload vulnerability in its document upload functionality. Authenticated users can upload files to the mods/documents/uploads/ directory without any restriction on file type or extension. Because this directory is publicly accessible and lacks execution controls, attackers can upload a malicious PHP payload and execute it remotely. The application ships with default credentials, making exploitation trivial. Once authenticated, the attacker can upload a PHP shell and trigger it via a direct GET request.
Exploits (3)
This Metasploit module exploits an arbitrary file upload vulnerability in PHP Volunteer Management System v1.0.2, allowing authenticated users to upload and execute malicious PHP payloads.
This is a writeup detailing two vulnerabilities in PHP Volunteer Management System v1.0.2: unrestricted file upload leading to RCE and persistent XSS. It provides PoC steps but no actual exploit code.
This Metasploit module exploits an arbitrary file upload vulnerability in PHP Volunteer Management System v1.0.2, allowing authenticated attackers to upload and execute malicious PHP files. The exploit leverages default credentials (admin:volunteer) to authenticate, uploads a PHP payload, and executes it by accessing the uploaded file.
References (5)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N