CVE-2013-10055

Havalite CMS 1.1.7 - Unauthenticated RCE

Title source: llm

Description

An unauthenticated arbitrary file upload vulnerability exists in Havalite CMS version 1.1.7 (and possibly earlier) in the upload.php script. The application fails to enforce proper file extension validation and authentication checks, allowing remote attackers to upload malicious PHP files via a crafted multipart/form-data POST request. Once uploaded, the attacker can access the file directly under havalite/tmp/files/, resulting in remote code execution.

Exploits (2)

metasploit WORKING POC EXCELLENT
by CWH, sinn3r · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/havalite_upload_exec.rb
exploitdb WORKING POC VERIFIED
by CWH Underground · textwebappsphp
https://www.exploit-db.com/exploits/26243

Scores

EPSS 0.7348
EPSS Percentile 98.8%

Classification

CWE
CWE-434
Status draft

Timeline

Published Aug 01, 2025
Tracked Since Feb 18, 2026