CVE-2016-1000031

CRITICAL

Apache Commons FileUpload <1.3.3 - RCE

Title source: llm

Description

Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution

Exploits (2)

nomisec WORKING POC
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2016-1000031-commons-fileupload-vulnerable
nomisec WORKING POC
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2016-1000031-commons-fileupload-vulnerable

References (24)

... and 4 more

Scores

CVSS v3 9.8
EPSS 0.5009
EPSS Percentile 97.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-284
Status published
Products (2)
apache/commons_fileupload < 1.3.2
commons-fileupload/commons-fileupload 0 - 1.3.3Maven
Published Oct 25, 2016
Tracked Since Feb 18, 2026