Back to search
CVE-2013-10040
Published: Jul 31, 2025
Modified: May 15, 2026
PUBLISHED
Description
ClipBucket version 2.6 and earlier contains a critical vulnerability in the ofc_upload_image.php script located at /admin_area/charts/ofc-library/. This endpoint allows unauthenticated users to upload arbitrary files, including executable PHP scripts. Once uploaded, the attacker can access the file via a predictable path and trigger remote code execution.
| Vendor | Product | Versions |
|---|---|---|
ClipBucket LLC | ClipBucket | affected 0 - <= 2.6 |
Weaknesses (CWE)
References
https://clipbucket.com/
product
https://www.vulncheck.com/advisories/clipbucket-arbitrary-file-upload-rce
third-party-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now