CVE-2013-10055
Havalite CMS 1.1.7 - Unauthenticated RCE
Title source: llmDescription
An unauthenticated arbitrary file upload vulnerability exists in Havalite CMS version 1.1.7 (and possibly earlier) in the upload.php script. The application fails to enforce proper file extension validation and authentication checks, allowing remote attackers to upload malicious PHP files via a crafted multipart/form-data POST request. Once uploaded, the attacker can access the file directly under havalite/tmp/files/, resulting in remote code execution.
Exploits (2)
metasploit
WORKING POC
EXCELLENT
by CWH, sinn3r · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/havalite_upload_exec.rb
exploitdb
WORKING POC
VERIFIED
by CWH Underground · textwebappsphp
https://www.exploit-db.com/exploits/26243
References (4)
Scores
EPSS
0.7348
EPSS Percentile
98.8%
Classification
CWE
CWE-434
Status
draft
Timeline
Published
Aug 01, 2025
Tracked Since
Feb 18, 2026