CVE-2013-10038
FlashChat Arbitrary File Upload RCE
Vexday Risk Score
63Prioridad alta
Decisión SSVC (CISA)
Attend
PoC disponible → seguir de cerca
CVSS 9.3EPSS 1.6%KEV nãoPoC públicaNuclei —Metasploit simPatch —
Ciclo de vida
04 oct 2013Exploit Metasploit disponible
31 jul 2025Publicada en NVD
Recomendación: Planificar corrección próxima — ya existe PoC pública.
An unauthenticated arbitrary file upload vulnerability exists in FlashChat versions 6.0.2 and 6.0.4 through 6.0.8. The upload.php endpoint fails to properly validate file types and authentication, allowing attackers to upload malicious PHP scripts. Once uploaded, these scripts can be executed remotely, resulting in arbitrary code execution as the web server user.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
TUFaT · FlashChatPoCs públicas encontradas — 2
cve_referenceraw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/flashchat_upload_exec.rbno verificadocve_referencewww.exploit-db.com/exploits/28709no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/flashchat_upload_exec.rbhttps://www.exploit-db.com/exploits/28709https://www.fortiguard.com/encyclopedia/ips/37342/flashchat-arbitrary-file-uploadhttps://www.phpbb.com/community/viewtopic.php?t=2627786https://www.vulncheck.com/advisories/flashchat-arbitrary-file-upload-rce