CVE-2011-4828
high · 7.5Unrestricted file upload vulnerability in includes/inline_image_upload.php in AutoSec Tools V-CMS 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in temp/.
7.5
CVSS
65.1%
EPSS (exploit prob.)
99th
EPSS percentile
2011-12-15
Published
AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| autosectools | v-cms | 1.0 |
Check a specific version with /api/v1/cve/match.
References
- http://bugs.v-cms.org/changelog_page.php
- http://bugs.v-cms.org/view.php?id=53
- http://secunia.com/advisories/46861
- http://www.autosectools.com/Advisory/V-CMS-1.0-Arbitrary-Upload-236
- http://www.securityfocus.com/bid/50706
- http://bugs.v-cms.org/changelog_page.php
- http://bugs.v-cms.org/view.php?id=53
- http://secunia.com/advisories/46861
- http://www.autosectools.com/Advisory/V-CMS-1.0-Arbitrary-Upload-236
- http://www.securityfocus.com/bid/50706
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2011-4828