Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2012-6583 | Sflog! CMS 1.0 contains an authenticated arbitrary file upload vulnerability in the blog management interface. The application ships with default credentials (admin:secret) and allows authenticated users to upload files via manage.php. The upload mechanism fails to validate file types, enabling attackers to upload a PHP backdoor into a web-accessible directory (blogs/download/uploads/). Once uploaded, the file can be executed remotely, resulting in full remote code execution. |
Tue, 12 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sflog
Sflog sflog |
|
| Vendors & Products |
Sflog
Sflog sflog |
Fri, 08 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 08 Aug 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sflog! CMS 1.0 contains an authenticated arbitrary file upload vulnerability in the blog management interface. The application ships with default credentials (admin:secret) and allows authenticated users to upload files via manage.php. The upload mechanism fails to validate file types, enabling attackers to upload a PHP backdoor into a web-accessible directory (blogs/download/uploads/). Once uploaded, the file can be executed remotely, resulting in full remote code execution. | |
| Title | Sflog! CMS 1.0 Arbitrary File Upload RCE | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:02:38.203Z
Reserved: 2025-08-07T20:09:09.351Z
Link: CVE-2012-10042
Updated: 2025-08-08T18:49:14.454Z
Status : Deferred
Published: 2025-08-08T19:15:34.000
Modified: 2026-04-15T00:35:42.020
Link: CVE-2012-10042
No data.
OpenCVE Enrichment
Updated: 2025-08-12T11:47:21Z
EUVD