CVE-2012-10056 describes an arbitrary file upload vulnerability in PHP Volunteer Management System v1.0.2, allowing authenticated users to upload unrestricted file types to a publicly accessible directory. This flaw carries a high CVSS score of 8.7, indicating a low-complexity attack that can lead to complete compromise of confidentiality, integrity, and availability. Exploitation is trivial due to default credentials and the availability of a Metasploit module, enabling remote code execution via a malicious PHP payload. While not on the KEV catalog, its high EPSS score and significant community discussion suggest a high likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| PHP Volunteer Management | PHP Volunteer Management | 1.0.2CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.