← back
CVE-2011-4828

CVE-2011-4828

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 65%
from disclosure to weapon121 days
Published on NVDDec 15
1st PoC+121d
metasploitNov 27
exploitation probability
65%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Unrestricted file upload vulnerability in includes/inline_image_upload.php in AutoSec Tools V-CMS 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in temp/.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.