nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25480 CVE-2019-25480
HIGH
ARMBot Unrestricted File Upload via upload.php
Record summary
CVE-2019-25480 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
ARMBot contains an unrestricted file upload vulnerability in upload.php that allows unauthenticated attackers to upload arbitrary files by manipulating the file parameter with path traversal sequences. Attackers can upload PHP files with traversal payloads ../public_html/ to write executable code to the web root and achieve remote code execution.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 11, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ARMBotBrowse ARMBot / ARMBotDefault status: unaffected | CVE List | * | affected |
Proofs of concept
1Catalogued exploits
ExploitDBARMBot Botnet - Arbitrary Code ExecutionExploitDB exploitby prsecurityNot analyzed1 file
References
4ExploitDB-47209exploit
https://www.exploit-db.com/exploits/47209 VulnCheck Advisory: ARMBot Unrestricted File Upload via upload.phpThird-party advisory
https://www.vulncheck.com/advisories/armbot-unrestricted-file-upload-via-upload-php vulncheck.com
https://www.vulncheck.com/advisories/armbot-unrestricted-file-upload-via-uploadphp