CVE-2013-10066
BaseFortify
Publication date: 2025-08-05
Last updated on: 2025-08-07
Assigner: VulnCheck
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| kordil | edms | 2.2.60rc3 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-434 | The product allows the upload or transfer of dangerous file types that are automatically processed within its environment. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an unauthenticated arbitrary file upload flaw in Kordil EDMS v2.2.60rc3. It allows attackers to upload files to the /userpictures/ directory without needing to log in. By uploading a malicious PHP file, an attacker can execute remote code on the server by accessing the uploaded file via HTTP.
How can this vulnerability impact me? :
The vulnerability can lead to remote code execution on the affected server, allowing attackers to run arbitrary commands, potentially take full control of the system, steal data, disrupt services, or use the server as a foothold for further attacks.