XODA version 0.4.5 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary PHP code on the server. The flaw resides in the upload functionality, which fails to properly validate or restrict uploaded file types. By crafting a multipart/form-data POST request, an attacker can upload a .php file directly into the web-accessible files/ directory and trigger its execution via a subsequent GET request.
History

Tue, 12 Aug 2025 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Xoda
Xoda xoda
Vendors & Products Xoda
Xoda xoda

Fri, 08 Aug 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 08 Aug 2025 18:30:00 +0000

Type Values Removed Values Added
Description XODA version 0.4.5 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary PHP code on the server. The flaw resides in the upload functionality, which fails to properly validate or restrict uploaded file types. By crafting a multipart/form-data POST request, an attacker can upload a .php file directly into the web-accessible files/ directory and trigger its execution via a subsequent GET request.
Title XODA 0.4.5 Arbitrary PHP File Upload
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-08-08T18:14:08.705Z

Updated: 2025-08-08T18:43:21.963Z

Reserved: 2025-08-08T13:52:20.773Z

Link: CVE-2012-10045

cve-icon Vulnrichment

Updated: 2025-08-08T18:43:10.248Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-08T19:15:34.450

Modified: 2025-08-08T20:30:18.180

Link: CVE-2012-10045

cve-icon Redhat

No data.