CVE-2012-6498

High PUBLISHED

Unrestricted file upload vulnerability in index.php in Atomymaxsite 2.5 and earlier allows remote attackers to execute arbitrary code by uploading...

Vendor: Atomymaxsite Product: Atomymaxsite

Not yet in CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
6.8 Medium EPSS 2.0%

At a Glance

Unrestricted file upload vulnerability in index.php in Atomymaxsite 2.5 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file, as exploited in the wild in October 2012.

php
CVE Published
Jan 08, 2013
Exploitation Reported
Jan 08, 2013
CVSS
6.8 Medium
EPSS
2.0%
Remote Unauthenticated

CVE References