CVE-2011-4828
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 65%
from disclosure to weapon121 days
Published on NVDDec 15
1st PoC+121d
metasploitNov 27
exploitation probability
65%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Unrestricted file upload vulnerability in includes/inline_image_upload.php in AutoSec Tools V-CMS 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in temp/.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/18738unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.