CVE-2012-3399

Basilic 1.5.14 - Remote Command Execution via Config/diff.php File Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2012-3399. PoCs published by Metasploit, lcashdollar, sinn3r, juan vazquez, including Metasploit module exploits/unix/webapp/basilic_diff_exec.

AI-analyzed exploit summary This Metasploit module exploits a metacharacter injection vulnerability in Basilic 1.5.14's diff.php script, allowing unauthenticated remote command execution as the www-data user. The exploit sends a crafted GET request with payload-encoded parameters to trigger arbitrary command execution.

Description

Config/diff.php in Basilic 1.5.14 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/19631

This Metasploit module exploits a metacharacter injection vulnerability in Basilic 1.5.14's diff.php script, allowing unauthenticated remote command execution as the www-data user. The exploit sends a crafted GET request with payload-encoded parameters to trigger arbitrary command execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Basilic 1.5.14
No auth needed
Prerequisites: Network access to the target · Basilic 1.5.14 installed with diff.php accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by lcashdollar, sinn3r, juan vazquez · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/basilic_diff_exec.rb

This Metasploit module exploits a metacharacter injection vulnerability in Basilic 1.5.14's diff.php script, allowing unauthenticated remote command execution as the www-data user. The exploit sends a crafted GET request with the payload embedded in the 'file' parameter.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Basilic 1.5.14
No auth needed
Prerequisites: Network access to the target · Basilic 1.5.14 installed with diff.php accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/76667
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-07/0043.html
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/07/09/4
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/19631
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/54234
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-07/0002.html
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/07/10/1

Scores

EPSS 0.6532
EPSS Percentile 99.2%

Details

CWE
CWE-20
Status published
Products (1)
artis.imag/basilic 1.5.14
Published Jul 12, 2012
Tracked Since Feb 18, 2026