PT-2025-32551 · Unknown · Auxilium Ratemypet

Published

2025-08-11

·

Updated

2025-08-11

·

CVE-2012-10038

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions: Auxilium RateMyPet (affected versions not specified)
Description: Auxilium RateMyPet contains an unauthenticated arbitrary file upload vulnerability in the upload banners.php file. The banner upload feature does not validate file types or require authentication, allowing remote attackers to upload malicious PHP files. These files are stored in the web-accessible /banners/ directory and can be executed directly, leading to remote code execution.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2012-10038

Affected Products

Auxilium Ratemypet