CVE-2016-1000031
CRITICALApache Commons FileUpload <1.3.3 - RCE
Title source: llmDescription
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
Exploits (2)
nomisec
WORKING POC
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2016-1000031-commons-fileupload-vulnerable
nomisec
WORKING POC
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2016-1000031-commons-fileupload-vulnerable
References (24)
... and 4 more
Scores
CVSS v3
9.8
EPSS
0.5009
EPSS Percentile
97.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-284
Status
published
Products (2)
apache/commons_fileupload
< 1.3.2
commons-fileupload/commons-fileupload
0 - 1.3.3Maven
Published
Oct 25, 2016
Tracked Since
Feb 18, 2026