CVE-2013-10055
CRITICALHavalite CMS 1.1.7 - Unauthenticated RCE
Title source: llmDescription
An unauthenticated arbitrary file upload vulnerability exists in Havalite CMS version 1.1.7 (and possibly earlier) in the upload.php script. The application fails to enforce proper file extension validation and authentication checks, allowing remote attackers to upload malicious PHP files via a crafted multipart/form-data POST request. Once uploaded, the attacker can access the file directly under havalite/tmp/files/, resulting in remote code execution.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by CWH Underground · textwebappsphp
https://www.exploit-db.com/exploits/26243
metasploit
WORKING POC
EXCELLENT
by CWH, sinn3r · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/havalite_upload_exec.rb
References (4)
Scores
CVSS v4
9.3
EPSS
0.7348
EPSS Percentile
98.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Details
CWE
CWE-434
Status
published
Products (1)
Havalite CMS/Havalite CMS
1.1.7
Published
Aug 01, 2025
Tracked Since
Feb 18, 2026