Vulnerability record · CVE-2011-4828 · published 15 December 2011
CVE-2011-4828: V-CMS unrestricted file upload leads to remote code execution
AAutosectools · V Cms
AutoSec Tools V-CMS 1.0 fails to restrict file types in includes/inline_image_upload.php, allowing an uploaded file with an executable extension to be stored and then run. Because the uploaded file is reachable directly under temp/, an unauthenticated attacker can turn a simple upload into code execution on the server.
Description
Unrestricted file upload vulnerability in includes/inline_image_upload.php in AutoSec Tools V-CMS 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in temp/.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with public exploit references and a very high EPSS score, though the product is an old, likely low-prevalence CMS.
What it is
AutoSec Tools V-CMS 1.0 fails to restrict file types in includes/inline_image_upload.php, allowing an uploaded file with an executable extension to be stored and then run. Because the uploaded file is reachable directly under temp/, an unauthenticated attacker can turn a simple upload into code execution on the server.
Impact
An attacker gains arbitrary code execution with the privileges of the web server, enabling data theft, defacement or further compromise of the host.
Attack surface
The flaw is reached over the network through the inline image upload endpoint, and the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication or user interaction is required. The uploaded file is then requested directly from temp/ to trigger execution.
Exploitation
CISA KEV does not list this CVE, but EPSS is high (0.651, 99.2nd percentile) and two references carry the Exploit tag, indicating public exploit material exists.
What to do
- Apply the vendor fix referenced in the V-CMS changelog and bug id 53, or upgrade past V-CMS 1.0.
- Restrict uploads to an allowlist of image extensions and validate MIME type and file content, not just the name.
- Store uploaded files outside the web root or in a directory where script execution is disabled.
- Block direct HTTP access to temp/ and any upload directory via web server configuration.
- Run the web service with least privilege and disable execution of scripts in writable directories.
Detection
- Monitor web logs for POSTs to includes/inline_image_upload.php followed by GET requests to temp/ files with executable extensions.
- Alert on files with .php, .phtml, .php5 or similar extensions appearing in temp/ or other upload directories.
- Watch for new or modified script files in web-accessible directories and for unexpected child processes spawned by the web server user.
- Review file integrity monitoring for changes under the V-CMS installation and upload paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-4828 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-4828), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.