CVE-2020-29597

CRITICAL EXPLOITED NUCLEI

IncomCMS 2.0 - Unauthenticated Unrestricted File Upload via modules/uploader/showcase/script.php

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2020-29597 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including MoeAlBarbari. A Nuclei detection template is also available.

AI-analyzed exploit summary This HTML form exploits an insecure file upload vulnerability in IncomCMS 2.0 by allowing arbitrary file uploads to a specific endpoint. The vulnerability can lead to remote code execution if the uploaded file is a malicious script.

Description

IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows unauthenticated attackers to upload files into the server.

Exploits (1)

exploitdb WORKING POC
by MoeAlBarbari · htmlwebappsmultiple
https://www.exploit-db.com/exploits/49351

This HTML form exploits an insecure file upload vulnerability in IncomCMS 2.0 by allowing arbitrary file uploads to a specific endpoint. The vulnerability can lead to remote code execution if the uploaded file is a malicious script.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: IncomCMS 2.0
No auth needed
Prerequisites: Access to the target's upload endpoint · Ability to send HTTP requests to the target
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Nuclei Templates (1)

IncomCMS 2.0 - Arbitrary File Upload
CRITICALVERIFIEDby princechaddha

References (3)

Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
https://m4dm0e.github.io/2020/12/07/incom-insecure-up.html
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/160784/Incom-CMS-2.0-File-Upload.html

Scores

CVSS v3 9.8
EPSS 0.8528
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-12-25
CWE
CWE-434
Status published
Products (1)
incomcms_project/incomcms 2.0
Published Dec 07, 2020
Tracked Since Feb 18, 2026