CVE-2012-10037 Information

Description

PhpTax version 0.8 contains a remote code execution vulnerability in drawimage.php. The pfilez GET parameter is unsafely passed to the exec() function without sanitization. A remote attacker can inject arbitrary shell commands leading to code execution under the web server’s context. No authentication is required.

Reference

https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/http/phptax_exec.rb https://sourceforge.net/projects/phptax/ https://www.exploit-db.com/exploits/21665 https://www.exploit-db.com/exploits/21833

CNNVD-202508-932 (Published: 2025-08-11)

Share on: