216.73.216.233

CVE-2012-10037

· Published 11/08/2025 15:15 · Modified 11/08/2025 18:32

Labels: CVE-2012-10037 2025-08-11CVE-2012-10037CWE-78[email protected]

Essential information

Published
11/08/2025 15:15
Modified
11/08/2025 18:32
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

PhpTax version 0.8 contains a remote code execution vulnerability in drawimage.php. The pfilez GET parameter is unsafely passed to the exec() function without sanitization. A remote attacker can inject arbitrary shell commands, leading to code execution under the web server's context. No authentication is required.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
phptax / phptax cpe:2.3:a:phptax:phptax:0.8:*:*:*:*:*:*:*

References