🔐 CVE Alert

CVE-2012-10036

UNKNOWN 0.0

Project Pier <= 0.8.8 Arbitrary File Upload RCE

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Project Pier 0.8.8 and earlier contains an unauthenticated arbitrary file upload vulnerability in tools/upload_file.php. The upload handler fails to validate the file type or enforce authentication, allowing remote attackers to upload malicious PHP files directly into a web-accessible directory. The uploaded file is stored with a predictable suffix and can be executed by requesting its URL, resulting in remote code execution.

CWE CWE-434
Vendor projectpier
Product projectpier
Published Aug 8, 2025
Last Updated Apr 7, 2026
Stay Ahead of the Next One

Get instant alerts for projectpier projectpier

Be the first to know when new unknown vulnerabilities affecting projectpier projectpier are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

ProjectPier / ProjectPier
* ≤ 0.8.8

References

NVD ↗ CVE.org ↗ EPSS Data ↗
raw.githubusercontent.com: https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/projectpier_upload_exec.rb exploit-db.com: https://www.exploit-db.com/exploits/21929 packetstorm.news: https://packetstorm.news/files/id/117070 web.archive.org: https://web.archive.org/web/20120111090432/http://www.projectpier.org/ opensourcecms.com: https://www.opensourcecms.com/projectpier/ vulncheck.com: https://www.vulncheck.com/advisories/project-pier-arbitrary-file-upload-rce

Credits

BlackHawk sinn3r