Critical severityNVD Advisory· Published Aug 8, 2025· Updated Apr 15, 2026
CVE-2012-10036
CVE-2012-10036
Description
Project Pier 0.8.8 and earlier contains an unauthenticated arbitrary file upload vulnerability in tools/upload_file.php. The upload handler fails to validate the file type or enforce authentication, allowing remote attackers to upload malicious PHP files directly into a web-accessible directory. The uploaded file is stored with a predictable suffix and can be executed by requesting its URL, resulting in remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=0.8.8
Patches
Vulnerability mechanics
References
6- packetstorm.news/files/id/117070nvd
- raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/projectpier_upload_exec.rbnvd
- web.archive.org/web/20120111090432/http://www.projectpier.org/nvd
- www.exploit-db.com/exploits/21929nvd
- www.opensourcecms.com/projectpier/nvd
- www.vulncheck.com/advisories/project-pier-arbitrary-file-upload-rcenvd
News mentions
0No linked articles in our index yet.