CVE-2013-4898

Timeline Plugin 4.2.5p9 for SocialEngine - Arbitrary File Upload & RCE via User Profile

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-4898. PoCs published by spyk2r.

AI-analyzed exploit summary This exploit leverages an arbitrary file upload vulnerability in the Timeline plugin for SocialEngine 4.5, allowing a PHP file to be uploaded despite validation errors. The uploaded file can then be accessed to execute system commands via a GET parameter.

Description

Unrestricted file upload vulnerability in the user profile page feature in the Timeline Plugin 4.2.5p9 for SocialEngine allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in public/temporary/timeline/.

Exploits (1)

exploitdb WORKING POC
by spyk2r · textwebappsphp
https://www.exploit-db.com/exploits/27272

This exploit leverages an arbitrary file upload vulnerability in the Timeline plugin for SocialEngine 4.5, allowing a PHP file to be uploaded despite validation errors. The uploaded file can then be accessed to execute system commands via a GET parameter.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Timeline plugin 4.2.5p9 for SocialEngine 4.5
Auth required
Prerequisites: Authenticated access to a user profile · Timeline plugin installed and active
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/527791
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/27272/

Scores

EPSS 0.0322
EPSS Percentile 86.6%

Details

Status published
Products (1)
webhive/timeline 4.2.5 p9
Published Jan 29, 2014
Tracked Since Feb 18, 2026