CVE-2012-1153

Apprain < 0.1.5 - Unrestricted File Upload

Title source: rule

Description

Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads directory.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/18922
exploitdb WORKING POC
by EgiX · phpwebappsphp
https://www.exploit-db.com/exploits/18392
metasploit WORKING POC EXCELLENT
by EgiX, sinn3r · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/apprain_upload_exec.rb

Scores

EPSS 0.8072
EPSS Percentile 99.1%

Details

Status published
Products (6)
apprain/apprain 0.1.0
apprain/apprain 0.1.1
apprain/apprain 0.1.2
apprain/apprain 0.1.3
apprain/apprain 0.1.4
apprain/apprain < 0.1.5
Published Oct 06, 2012
Tracked Since Feb 18, 2026