CVE-2013-10040

CRITICAL

ClipBucket < 2.6 - Unauthenticated Arbitrary File Upload and Remote Code Execution via ofc_upload_image.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-10040. PoCs published by Gabby, including Metasploit module exploits/unix/webapp/clipbucket_upload_exec.

AI-analyzed exploit summary This Metasploit module exploits an unauthenticated arbitrary file upload vulnerability in ClipBucket 2.6 and lower via the `/admin_area/charts/ofc-library/ofc_upload_image.php` endpoint, allowing remote code execution by uploading a malicious PHP payload.

Description

ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofc_upload_image.php script located at /admin_area/charts/ofc-library/. This endpoint allows unauthenticated users to upload arbitrary files, including executable PHP scripts. Once uploaded, the attacker can access the file via a predictable path and trigger remote code execution.

Exploits (1)

metasploit WORKING POC EXCELLENT
by Gabby · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/clipbucket_upload_exec.rb

This Metasploit module exploits an unauthenticated arbitrary file upload vulnerability in ClipBucket 2.6 and lower via the `/admin_area/charts/ofc-library/ofc_upload_image.php` endpoint, allowing remote code execution by uploading a malicious PHP payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: ClipBucket <= 2.6
No auth needed
Prerequisites: Network access to the target · ClipBucket version <= 2.6
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.7717
EPSS Percentile 99.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-434
Status published
Products (2)
clip-bucket/clipbucket < 2.6
ClipBucket LLC/ClipBucket < 2.6
Published Jul 31, 2025
Tracked Since Feb 18, 2026