CVE-2013-10038 – FlashChat Arbitrary File Upload Vulnerability

The following table lists the changes that have been made to the
CVE-2013-10038 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jul. 31, 2025

    Action Type Old Value New Value
    Added Tag unsupported-when-assigned
    Added Description An unauthenticated arbitrary file upload vulnerability exists in FlashChat versions 6.0.2 and 6.0.4 through 6.0.8. The upload.php endpoint fails to properly validate file types and authentication, allowing attackers to upload malicious PHP scripts. Once uploaded, these scripts can be executed remotely, resulting in arbitrary code execution as the web server user.
    Added CVSS V4.0 AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CWE CWE-434
    Added Reference https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/flashchat_upload_exec.rb
    Added Reference https://www.exploit-db.com/exploits/28709
    Added Reference https://www.fortiguard.com/encyclopedia/ips/37342/flashchat-arbitrary-file-upload
    Added Reference https://www.phpbb.com/community/viewtopic.php?t=2627786
    Added Reference https://www.vulncheck.com/advisories/flashchat-arbitrary-file-upload-rce
Share the Post:

Related Posts