← Vulnerability feed

Vulnerability record · CVE-2011-4828 · published 15 December 2011

CVE-2011-4828: V-CMS unrestricted file upload leads to remote code execution

AAutosectools · V Cms

AutoSec Tools V-CMS 1.0 fails to restrict file types in includes/inline_image_upload.php, allowing an uploaded file with an executable extension to be stored and then run. Because the uploaded file is reachable directly under temp/, an unauthenticated attacker can turn a simple upload into code execution on the server.

7.5 CVSS 2.0 High EPSS 65% · top 0.8% CWE-94 · Code injection
7.5CVSS 2.0 base score
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Unrestricted file upload vulnerability in includes/inline_image_upload.php in AutoSec Tools V-CMS 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in temp/.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityUnauthenticated remote code execution with public exploit references and a very high EPSS score, though the product is an old, likely low-prevalence CMS.

What it is

AutoSec Tools V-CMS 1.0 fails to restrict file types in includes/inline_image_upload.php, allowing an uploaded file with an executable extension to be stored and then run. Because the uploaded file is reachable directly under temp/, an unauthenticated attacker can turn a simple upload into code execution on the server.

Impact

An attacker gains arbitrary code execution with the privileges of the web server, enabling data theft, defacement or further compromise of the host.

Attack surface

The flaw is reached over the network through the inline image upload endpoint, and the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication or user interaction is required. The uploaded file is then requested directly from temp/ to trigger execution.

Exploitation

CISA KEV does not list this CVE, but EPSS is high (0.651, 99.2nd percentile) and two references carry the Exploit tag, indicating public exploit material exists.

What to do

  • Apply the vendor fix referenced in the V-CMS changelog and bug id 53, or upgrade past V-CMS 1.0.
  • Restrict uploads to an allowlist of image extensions and validate MIME type and file content, not just the name.
  • Store uploaded files outside the web root or in a directory where script execution is disabled.
  • Block direct HTTP access to temp/ and any upload directory via web server configuration.
  • Run the web service with least privilege and disable execution of scripts in writable directories.

Detection

  • Monitor web logs for POSTs to includes/inline_image_upload.php followed by GET requests to temp/ files with executable extensions.
  • Alert on files with .php, .phtml, .php5 or similar extensions appearing in temp/ or other upload directories.
  • Watch for new or modified script files in web-accessible directories and for unexpected child processes spawned by the web server user.
  • Review file integrity monitoring for changes under the V-CMS installation and upload paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-4828 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.8CVE-2011-4826Autosectools v-cms sql injection vulnerabilitySQL injection vulnerability in session.php in AutoSec Tools V-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the user paramete…EPSS 1.1%4.3CVE-2011-4827Autosectools v-cms cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in AutoSec Tools V-CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the …EPSS 1.1%8.8CVE-2026-65660Microsoft sharepoint server code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.KEVEPSS 2.1%9.8CVE-2026-60004Gitea diffpatch API code injection enables remote code executionGitea before 1.27.1 allows remote code execution through the diffpatch API by way of Git hook installation. The flaw is a code injection issue (CWE-9…KEVEPSS 24%analysed9.5CVE-2026-72530TrueConf Server sandbox breakout via crafted script code injectionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5 and earlier allow a remote unauthenticated attacker to break o…KEVEPSS 1.7%analysed9.4CVE-2025-62593Ray browser-based RCE via insufficient User-Agent guardRay, an AI compute engine, contains a critical remote code execution flaw before version 2.52.0. Its defense against browser-based attacks relies on …KEVEPSS 62%analysed9.8CVE-2026-9198Langflow auto_login and code validation chain enables unauthenticated RCEIBM Langflow OSS 1.0.0 through 1.10.0 exposes /api/v1/auto_login, which mints SUPERUSER tokens to any network caller, and /api/v1/validate/code, whic…KEVEPSS 29%analysed7.2CVE-2026-15410SonicWall SMA1000 AMC code injection allows OS command executionThe SMA1000 Appliance Management Console (AMC) contains a post-authentication code injection flaw (CWE-94) that, under specific conditions, lets an a…KEVEPSS 12%analysed

Source: NIST National Vulnerability Database (record CVE-2011-4828), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.