CVE-2013-10040: ClipBucket <= 2.6 ofc_upload_image.php Arbitrary File Upload RCE
ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofcuploadimage.php script located at /adminarea/charts/ofc-library/. This endpoint allows unauthenticated users to upload arbitrary files, including executable PHP scripts. Once uploaded, the attacker can access the file via a predictable path and trigger remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-10040?
CVE-2013-10040 is considered critical due to its exploitability by unauthenticated users.
How do I fix CVE-2013-10040?
To fix CVE-2013-10040, upgrade to a version of ClipBucket later than 2.6 that addresses the vulnerability.
What type of attacks can CVE-2013-10040 enable?
CVE-2013-10040 can enable attackers to upload arbitrary files, including malicious PHP scripts, to the server.
Which software versions are affected by CVE-2013-10040?
CVE-2013-10040 affects ClipBucket version 2.6 and earlier.
Where is the vulnerability in CVE-2013-10040 located?
The vulnerability in CVE-2013-10040 is located in the ofc_upload_image.php script within the /admin_area/charts/ofc-library/ directory.