NONE · 0

CVE-2012-10038

Auxilium RateMyPet contains an unauthenticated arbitrary file upload vulnerability in upload_banners.php. The banner upload feature fails to validate file types or enforce authentication, allowing rem...

Vulnerability Description

Auxilium RateMyPet contains an unauthenticated arbitrary file upload vulnerability in upload_banners.php. The banner upload feature fails to validate file types or enforce authentication, allowing remote attackers to upload malicious PHP files. These files are stored in a web-accessible /banners/ directory and can be executed directly, resulting in remote code execution.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-10038?

CVE-2012-10038 is a documented vulnerability. Auxilium RateMyPet contains an unauthenticated arbitrary file upload vulnerability in upload_banners.php. The banner upload feature fails to validate file types or enforce authentication, allowing rem...

How severe is CVE-2012-10038?

CVSS scoring is not yet available for CVE-2012-10038. Check NVD for updates.

Is there a patch for CVE-2012-10038?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.