CVE-2013-10047 - CVE House
Back to Database
Status published Critical CVE-2013-10047

MiniWeb <= Build 300 Arbitrary File Upload

Vulnerability Description

An unrestricted file upload vulnerability exists in MiniWeb HTTP Server <= Build 300 that allows unauthenticated remote attackers to upload arbitrary files to the server’s filesystem. By abusing the upload handler and crafting a traversal path, an attacker can place a malicious .exe in system32, followed by a .mof file in the WMI directory. This triggers execution of the payload with SYSTEM privileges via the Windows Management Instrumentation service. The exploit is only viable on Windows versions prior to Vista.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-10047

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • AkaStep

Affected Vendor

Affected Software

MiniWeb
Vulnerable Versions:
0

Timeline

Official Publish: August 1st, 2025
Last Modified: May 15th, 2026
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)