« Volver al listado

CVE-2012-6498

Estado: ModificadaMedia (6.8)—

Unrestricted file upload vulnerability in index.php in Atomymaxsite 2.5 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file, as exploited in the wild in October 2012.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-6498",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-01-08T15:55:03.007",
  "references": [
    {
      "url": "http://thaicert.or.th/alerts/admin/2012/al2012ad025.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.youtube.com/watch?v=CfvTCSS3LGY",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://thaicert.or.th/alerts/admin/2012/al2012ad025.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.youtube.com/watch?v=CfvTCSS3LGY",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Unrestricted file upload vulnerability in index.php in Atomymaxsite 2.5 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file, as exploited in the wild in October 2012."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de subida de ficheros sin restricción en index.php en Atomymaxsite v2.5 y anteriores permite a atacantes remotos ejecutar código arbitrario mediante la carga de un archivo con una extensión ejecutable y accediendo al archivo a través de una solicitud directa, como se explota en octubre de 2012."
    }
  ],
  "lastModified": "2026-06-16T23:48:14.497",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:maxtom:atomymaxsite:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E05787F5-CAD7-45D1-B266-2493D9F7CB42",
              "versionEndIncluding": "2.5"
            },
            {
              "criteria": "cpe:2.3:a:maxtom:atomymaxsite:1.50:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DDED3992-68E7-4C25-B1A2-4C87A618615F"
            },
            {
              "criteria": "cpe:2.3:a:maxtom:atomymaxsite:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3BD347F4-2C12-40AA-ABBE-580BD7D7B9BD"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "Per: http://cwe.mitre.org/data/definitions/434.html 'CWE-434: Unrestricted Upload of File with Dangerous Type'",
  "sourceIdentifier": "cve@mitre.org"
}