Vulnerability Description
Unrestricted file upload vulnerability in index.php in Atomymaxsite 2.5 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file, as exploited in the wild in October 2012.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Maxtom | Atomymaxsite | <= 2.5 |
References
- http://thaicert.or.th/alerts/admin/2012/al2012ad025.html
- http://www.youtube.com/watch?v=CfvTCSS3LGY
- http://thaicert.or.th/alerts/admin/2012/al2012ad025.html
- http://www.youtube.com/watch?v=CfvTCSS3LGY
FAQ
What is CVE-2012-6498?
CVE-2012-6498 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Unrestricted file upload vulnerability in index.php in Atomymaxsite 2.5 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing i...
How severe is CVE-2012-6498?
CVE-2012-6498 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-6498?
Check the references section above for vendor advisories and patch information. Affected products include: Maxtom Atomymaxsite.