Glossword 1.8.8 - 1.8.12 Arbitrary File Upload RCE
Vulnerability Description
Glossword versions 1.8.8 through 1.8.12 contain an authenticated arbitrary file upload vulnerability. When deployed as a standalone application, the administrative interface (gw_admin.php) allows users with administrator privileges to upload files to the gw_temp/a/ directory. Due to insufficient validation of file type and path, attackers can upload and execute PHP payloads, resulting in remote code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-10067
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- AkaStep
References
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/http/glossword_upload_exec.rb
- https://www.exploit-db.com/exploits/24456
- https://www.exploit-db.com/exploits/24548
- https://github.com/glosswordteam/Glossword
- https://sourceforge.net/projects/glossword/
- https://www.vulncheck.com/advisories/glossword-arbitrary-file-upload-rce
Affected Vendor
Glossword Team
View all reports →