PHP Volunteer Management System 1.0.2 Arbitrary File Upload
36Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 8.7epss 1.0%
from disclosure to weapon0 days
Published on NVDAug 13
metasploitMay 28
exploitation probability
1.0%top 38% of all CVEs
observed exploitation
nono source reports it
PHP Volunteer Management System v1.0.2 contains an arbitrary file upload vulnerability in its document upload functionality. Authenticated users can upload files to the mods/documents/uploads/ directory without any restriction on file type or extension. Because this directory is publicly accessible and lacks execution controls, attackers can upload a malicious PHP payload and execute it remotely. The application ships with default credentials, making exploitation trivial. Once authenticated, the attacker can upload a PHP shell and trigger it via a direct GET request.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
PHP Volunteer Management · PHP Volunteer ManagementReferences
https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/http/php_volunteer_upload_exec.rbhttps://sourceforge.net/projects/phpvolunteer/https://www.exploit-db.com/exploits/18941https://www.exploit-db.com/exploits/18957https://www.vulncheck.com/advisories/php-volunteer-management-system-arbitrary-file-upload