CVE-2013-10047 PUBLISHED

MiniWeb <= Build 300 Arbitrary File Upload

Assigner: VulnCheck
Reserved: 01.08.2025 Published: 01.08.2025 Updated: 06.08.2025

An unrestricted file upload vulnerability exists in MiniWeb HTTP Server <= Build 300 that allows unauthenticated remote attackers to upload arbitrary files to the server’s filesystem. By abusing the upload handler and crafting a traversal path, an attacker can place a malicious .exe in system32, followed by a .mof file in the WMI directory. This triggers execution of the payload with SYSTEM privileges via the Windows Management Instrumentation service. The exploit is only viable on Windows versions prior to Vista.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor MiniWeb
Product MiniWeb
Versions Default: unknown
  • affected from * to Build 300 (incl.)

Credits

  • AkaStep finder

References

Problem Types

  • CWE-434 Unrestricted Upload of File with Dangerous Type CWE

Impacts

  • CAPEC-233 Privilege Escalation