thaicert.or.th
http://thaicert.or.th/alerts/admin/2012/al2012ad025.html CVE-2012-6498
maxtom atomymaxsite Unrestricted Upload of File with Dangerous Type
Record summary
CVE-2012-6498 has a selected CVSS score of 6.8.
Description
Unrestricted file upload vulnerability in index.php in Atomymaxsite 2.5 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file, as exploited in the wild in October 2012.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 8, 2013 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
atomymaxsiteBrowse maxtom / atomymaxsite | VulnCheck | Version data not supplied | |
References
3youtube.com
http://www.youtube.com/watch?v=CfvTCSS3LGY nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2012-6498