CVE-2013-10040 - CVE House
Back to Database
Status published Critical CVE-2013-10040

ClipBucket <= 2.6 ofc_upload_image.php Arbitrary File Upload RCE

Vulnerability Description

ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofc_upload_image.php script located at /admin_area/charts/ofc-library/. This endpoint allows unauthenticated users to upload arbitrary files, including executable PHP scripts. Once uploaded, the attacker can access the file via a predictable path and trigger remote code execution.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-10040

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Gabby

Affected Vendor

ClipBucket LLC

View all reports →

Affected Software

ClipBucket
Vulnerable Versions:
0

Timeline

Official Publish: July 31st, 2025
Last Modified: May 15th, 2026
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)