CVE-2012-10037 describes a critical remote code execution vulnerability in PhpTax version 0.8, specifically within the drawimage.php component. An attacker can inject arbitrary shell commands via the unsanitized pfilez GET parameter, leading to code execution on the web server without requiring authentication. This vulnerability carries a CVSS score of 9.3 (Critical) due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, exploit modules are publicly available, including a Metasploit module, and the vulnerability has garnered significant community discussion, indicating a high potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| PhpTax | PhpTax | 0.8CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.