CVE-2012-10042 describes an authenticated arbitrary file upload vulnerability in Sflog! CMS 1.0. The flaw allows authenticated users, including those using default credentials (admin:secret), to upload malicious PHP files due to insufficient file type validation in the blog management interface. This vulnerability carries a high severity CVSS score of 8.7, indicating a network-exploitable flaw with low attack complexity that can lead to full remote code execution. While not listed on the KEV catalog, a Metasploit module exists, and the vulnerability has garnered significant community discussion, suggesting a high potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Sflog! | Sflog! CMS | 1.0CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.