Idera Up.Time ≤ 7.2 post2file.php Arbitrary File Upload RCE
Vulnerability Description
An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and including 7.2. The `wizards/post2file.php` script accepts arbitrary POST parameters, allowing attackers to upload crafted PHP files to the webroot. Successful exploitation results in remote code execution as the web server user. NOTE: The bypass for this vulnerability is tracked as CVE-2015-9263.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34121
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Denis Andzakovic of Security-Assessment.com
References
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/http/uptime_file_upload_1.rb
- https://web.archive.org/web/20150210113937/http://www.security-assessment.com/files/documents/advisory/Up.Time%207.2%20-%20Arbitrary%20File%20Upload.pdf
- https://www.exploit-db.com/exploits/38732
- https://www.vulncheck.com/advisories/idera-uptime-arbitrary-file-upload-rce
Affected Vendor
Idera
View all reports →