Vulnerability record · CVE-2012-3399 · published 12 July 2012
CVE-2012-3399: Basilic diff.php command injection via file parameter
AArtis.Imag · Basilic
Config/diff.php in Basilic 1.5.14 passes the file parameter to a shell without sanitizing shell metacharacters, allowing remote command execution. The flaw is improper input validation (CWE-20) and is reachable over the network without authentication.
Description
Config/diff.php in Basilic 1.5.14 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote command execution with public exploit code and very high EPSS, though no KEV listing or confirmed active exploitation is recorded.
What it is
Config/diff.php in Basilic 1.5.14 passes the file parameter to a shell without sanitizing shell metacharacters, allowing remote command execution. The flaw is improper input validation (CWE-20) and is reachable over the network without authentication.
Impact
An unauthenticated remote attacker can execute arbitrary commands on the host running Basilic, gaining the privileges of the web server process.
Attack surface
Reached over the network via HTTP requests to Config/diff.php with crafted shell metacharacters in the file parameter. The CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Public exploit code exists (Exploit-DB 19631 and SecurityFocus BID 54234 are tagged Exploit), and EPSS is 0.653 with a 99.2 percentile. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is documented in this record.
What to do
- Apply the vendor fix for Basilic or upgrade past 1.5.14 if a fixed release exists; the record does not name a patched version.
- If no patch is available, remove or disable Config/diff.php and restrict access to the Basilic installation.
- Validate and whitelist the file parameter, rejecting shell metacharacters, and avoid passing user input to shell commands.
- Run Basilic with least privilege and isolate it from sensitive systems.
Detection
- Monitor web logs for requests to Config/diff.php containing shell metacharacters such as ;, |, &&, $(), or backticks in the file parameter.
- Alert on unexpected child processes spawned by the web server user, especially shells or command interpreters.
- Review outbound connections and file writes originating from the Basilic process for signs of post-exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-3399 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-3399), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.