Auxilium RateMyPet Arbitrary File Upload RCE
Vulnerability Description
Auxilium RateMyPet contains an unauthenticated arbitrary file upload vulnerability in upload_banners.php. The banner upload feature fails to validate file types or enforce authentication, allowing remote attackers to upload malicious PHP files. These files are stored in a web-accessible /banners/ directory and can be executed directly, resulting in remote code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-10038
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- DaOne
Affected Vendor
Auxilium
View all reports →