CVE-2013-4898

Timeline Plugin 4.2.5p9 - RCE

Title source: llm
STIX 2.1

Description

Unrestricted file upload vulnerability in the user profile page feature in the Timeline Plugin 4.2.5p9 for SocialEngine allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in public/temporary/timeline/.

Exploits (1)

exploitdb WORKING POC
by spyk2r · textwebappsphp
https://www.exploit-db.com/exploits/27272

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/527791
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/27272/

Scores

EPSS 0.0884
EPSS Percentile 92.6%

Details

Status published
Products (1)
webhive/timeline 4.2.5 p9
Published Jan 29, 2014
Tracked Since Feb 18, 2026