CVE-2012-10045
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-08-08

Last updated on: 2025-08-08

Assigner: VulnCheck

Description
XODA version 0.4.5 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary PHP code on the server. The flaw resides in the upload functionality, which fails to properly validate or restrict uploaded file types. By crafting a multipart/form-data POST request, an attacker can upload a .php file directly into the web-accessible files/ directory and trigger its execution via a subsequent GET request.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-08-08
Last Modified
2025-08-08
Generated
2026-05-06
AI Q&A
2025-08-08
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
xoda xoda 0.4.5
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in XODA version 0.4.5 and allows unauthenticated remote attackers to upload arbitrary PHP files to the server. The upload functionality does not properly validate or restrict the types of files that can be uploaded. An attacker can send a specially crafted multipart/form-data POST request to upload a .php file into a web-accessible directory and then execute that file by making a subsequent GET request, leading to remote code execution on the server.


How can this vulnerability impact me? :

This vulnerability can have severe impacts including allowing attackers to execute arbitrary PHP code on the affected server without authentication. This can lead to full compromise of the server, unauthorized access to sensitive data, defacement, data loss, or use of the server as a launch point for further attacks.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart