CVE-2012-10064
CRITICAL EXPLOITEDOmni Secure Files < 0.1.14 - Unauthenticated Arbitrary File Upload via plupload Example Endpoint
Title source: llmExploitation Summary
CVE-2012-10064 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Adrien Thierry.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file upload vulnerability in WordPress Omni-secure-files 0.1.13. It uses cURL to upload a malicious PHP file to the vulnerable upload.php endpoint, allowing remote code execution.
Description
Omni Secure Files plugin versions prior to 0.1.14 contain an arbitrary file upload vulnerability in the bundled plupload example endpoint. The /wp-content/plugins/omni-secure-files/plupload/examples/upload.php handler allows unauthenticated uploads without enforcing safe file type restrictions, enabling an attacker to place attacker-controlled files under the plugin's uploads directory. This can lead to remote code execution if a server-executable file type is uploaded and subsequently accessed.
Exploits (1)
This exploit demonstrates an arbitrary file upload vulnerability in WordPress Omni-secure-files 0.1.13. It uses cURL to upload a malicious PHP file to the vulnerable upload.php endpoint, allowing remote code execution.
References (9)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N