← volver
CVE-2013-10032

GetSimple CMS 3.2.1 Authenticated RCE via Arbitrary PHP File Upload

CVSS 8.7 HIGHEPSS 2.5%CWE-306CWE-434
Vexday Risk Score
36Atención
Decisión SSVC (CISA)
Attend
PoC disponible → seguir de cerca
CVSS 8.7EPSS 2.5%KEV nãoPoC Nuclei Metasploit simPatch
Ciclo de vida
04 ene 2014Exploit Metasploit disponible
25 jul 2025Publicada en NVD
Recomendación: Planificar corrección próxima — ya existe PoC pública.
An authenticated remote code execution vulnerability exists in GetSimpleCMS version 3.2.1. The application’s upload.php endpoint allows authenticated users to upload arbitrary files without proper validation of MIME types or extensions. By uploading a .pht file containing PHP code, an attacker can bypass blacklist-based restrictions and place executable code within the web root. A crafted request using a polyglot or disguised extension allows the attacker to execute the payload by accessing the file directly via the web server. This vulnerability exists due to the use of a blacklist for filtering file types instead of a whitelist.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →