CVE-2013-10040
CRITICALClipBucket < 2.6 - Unauthenticated Arbitrary File Upload and Remote Code Execution via ofc_upload_image.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-10040.
PoCs published by Gabby, including Metasploit module exploits/unix/webapp/clipbucket_upload_exec.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated arbitrary file upload vulnerability in ClipBucket 2.6 and lower via the `/admin_area/charts/ofc-library/ofc_upload_image.php` endpoint, allowing remote code execution by uploading a malicious PHP payload.
Description
ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofc_upload_image.php script located at /admin_area/charts/ofc-library/. This endpoint allows unauthenticated users to upload arbitrary files, including executable PHP scripts. Once uploaded, the attacker can access the file via a predictable path and trigger remote code execution.
Exploits (1)
This Metasploit module exploits an unauthenticated arbitrary file upload vulnerability in ClipBucket 2.6 and lower via the `/admin_area/charts/ofc-library/ofc_upload_image.php` endpoint, allowing remote code execution by uploading a malicious PHP payload.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H