Record summary

CVE-2013-10038 has a selected CVSS score of 9.3 (critical); EIP currently links 2 catalogued exploits.

Description

An unauthenticated arbitrary file upload vulnerability exists in FlashChat versions 6.0.2 and 6.0.4 through 6.0.8. The upload.php endpoint fails to properly validate file types and authentication, allowing attackers to upload malicious PHP scripts. Once uploaded, these scripts can be executed remotely, resulting in arbitrary code execution as the web server user.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 31, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List6.0.2affected
6.0.4 to ≤ 6.0.8affected

Proofs of concept

2

Catalogued exploits

ExploitDBFlashChat 6.0.2 < 6.0.8 - Arbitrary File UploadExploitDB exploitby x-hayben21Not analyzed1 file
ExploitDB

PoC details
MetasploitFlashChat Arbitrary File UploadMetasploit exploitby bcoles <bcoles@gmail.com> +1 moreNot analyzed1 file

Ruby

Metasploit

PoC details

References

6