Unrated severityNVD Advisory· Published Oct 6, 2012· Updated Apr 29, 2026
CVE-2012-1153
CVE-2012-1153
Description
Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads directory.
Affected products
6cpe:2.3:a:apprain:apprain:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:apprain:apprain:*:*:*:*:*:*:*:*range: <=0.1.5
- cpe:2.3:a:apprain:apprain:0.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:apprain:apprain:0.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:apprain:apprain:0.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:apprain:apprain:0.1.3:*:*:*:*:*:*:*
- cpe:2.3:a:apprain:apprain:0.1.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- archives.neohapsis.com/archives/bugtraq/2012-01/0128.htmlnvdExploit
- www.exploit-db.com/exploits/18392nvdExploit
- www.securityfocus.com/bid/51576nvdExploit
- www.exploit-db.com/exploits/18922nvd
- www.openwall.com/lists/oss-security/2012/03/09/5nvd
- www.openwall.com/lists/oss-security/2012/03/10/5nvd
- www.osvdb.org/78473nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/72466nvd
News mentions
0No linked articles in our index yet.