Auxilium RateMyPet contains an unauthenticated arbitrary file upload vulnerability in upload_banners.php. The banner upload feature fails to validate file types or enforce authentication, allowing remote attackers to upload malicious PHP files. These files are stored in a web-accessible /banners/ directory and can be executed directly, resulting in remote code execution.
CVSS
No CVSS.
References
Configurations
No configuration.
History
11 Aug 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-11 15:15
Updated : 2025-08-11 18:32
NVD link : CVE-2012-10038
Mitre link : CVE-2012-10038
CVE.ORG link : CVE-2012-10038
JSON object : View
Products Affected
No product.
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type