Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as used in Piwik 0.2.35 through 0.4.3, Woopra Analytics Plugin before 1.4.3.2, and possibly other products, when register_globals is enabled, allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension through the name parameter with the code in the HTTP_RAW_POST_DATA parameter, then accessing it via a direct request to the file in tmp-upload-images/
Published Dec 22, 2009
7.5
HIGHCVSS 2.0
EPSS 75.84%
Description
Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer, as used in Piwik 0.2.35 through 0.4.3, Woopra Analytics Plugin before 1.4.3.2, and possibly other products, when register_globals is enabled, allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension through the name parameter with the code in the HTTP_RAW_POST_DATA parameter, then accessing it via a direct request to the file in tmp-upload-images/.
Affected products
No data.
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
- 2.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (39 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 75.84% (0.75838) | 99.51th | v5 (v2026.06.15) |
| Jun 15, 2026 | 75.84% (0.75838) | 99.46th | v5 (v2026.06.15) |
| Mar 4, 2026 | 91.09% (0.91085) | 99.63th | v4 (v2025.03.14) |
| Mar 1, 2026 | 87.03% (0.87026) | 99.43th | v4 (v2025.03.14) |
| Feb 4, 2026 | 91.09% (0.91085) | 99.63th | v4 (v2025.03.14) |
| Feb 1, 2026 | 87.03% (0.87026) | 99.43th | v4 (v2025.03.14) |
| Jan 4, 2026 | 91.09% (0.91085) | 99.62th | v4 (v2025.03.14) |
| Jan 1, 2026 | 87.03% (0.87026) | 99.42th | v4 (v2025.03.14) |
| Dec 4, 2025 | 91.09% (0.91085) | 99.62th | v4 (v2025.03.14) |
| Dec 1, 2025 | 87.03% (0.87026) | 99.41th | v4 (v2025.03.14) |
| Nov 4, 2025 | 91.09% (0.91085) | 99.62th | v4 (v2025.03.14) |
| Nov 1, 2025 | 87.03% (0.87026) | 99.41th | v4 (v2025.03.14) |
| Oct 4, 2025 | 91.09% (0.91085) | 99.63th | v4 (v2025.03.14) |
| Oct 1, 2025 | 87.03% (0.87026) | 99.42th | v4 (v2025.03.14) |
| Sep 4, 2025 | 91.09% (0.91085) | 99.63th | v4 (v2025.03.14) |
| Sep 1, 2025 | 87.03% (0.87026) | 99.42th | v4 (v2025.03.14) |
| Aug 4, 2025 | 91.09% (0.91085) | 99.62th | v4 (v2025.03.14) |
| Aug 1, 2025 | 87.03% (0.87026) | 99.41th | v4 (v2025.03.14) |
| Jul 5, 2025 | 91.75% (0.91745) | 99.66th | v4 (v2025.03.14) |
| Jul 1, 2025 | 87.03% (0.87026) | 99.41th | v4 (v2025.03.14) |
| Jun 6, 2025 | 91.75% (0.91745) | 99.66th | v4 (v2025.03.14) |
| Jun 1, 2025 | 87.03% (0.87026) | 99.41th | v4 (v2025.03.14) |
| May 4, 2025 | 91.75% (0.91745) | 99.66th | v4 (v2025.03.14) |
| May 1, 2025 | 87.03% (0.87026) | 99.39th | v4 (v2025.03.14) |
| Apr 13, 2025 | 91.75% (0.91745) | 99.67th | v4 (v2025.03.14) |
| Apr 12, 2025 | 87.03% (0.87026) | 99.41th | v4 (v2025.03.14) |
| Apr 2, 2025 | 91.75% (0.91745) | 99.67th | v4 (v2025.03.14) |
| Apr 1, 2025 | 87.03% (0.87026) | 99.40th | v4 (v2025.03.14) |
| Mar 25, 2025 | 91.75% (0.91745) | 99.68th | v4 (v2025.03.14) |
| Mar 24, 2025 | 87.03% (0.87026) | 99.41th | v4 (v2025.03.14) |
| Mar 17, 2025 | 91.45% (0.91454) | 99.66th | v4 (v2025.03.14) |
| Dec 12, 2024 | 97.28% (0.97276) | 99.89th | v3 (v2023.03.01) |
| Dec 25, 2023 | 97.28% (0.97276) | 99.83th | v3 (v2023.03.01) |
| Nov 10, 2023 | 97.20% (0.97200) | 99.78th | v3 (v2023.03.01) |
| Sep 27, 2023 | 97.12% (0.97117) | 99.70th | v3 (v2023.03.01) |
| Jul 3, 2023 | 97.26% (0.97264) | 99.76th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.28% (0.97280) | 99.71th | v3 (v2023.03.01) |
| Mar 6, 2023 | 90.82% (0.90816) | 99.87th | v2 (v2022.01.01) |
| Feb 4, 2022 | 90.82% (0.90816) | 99.84th | v2 (v2022.01.01) |
No CWE recorded.
References (16)
- http://packetstormsecurity.com/files/123493/wpseowatcher-exec.txt x_refsource_MISC
- http://packetstormsecurity.com/files/123494/wpslimstatex-exec.txt x_refsource_MISC
- http://packetstormsecurity.org/0910-exploits/piwik-upload.txt x_refsource_MISCExploit
- http://piwik.org/blog/2009/10/piwik-response-to-secunia-advisory-sa37078/ x_refsource_CONFIRMVendor Advisory
- http://secunia.com/advisories/37078 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/37911 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/55160 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/55162 third-party-advisoryx_refsource_SECUNIA
- http://wordpress.org/extend/plugins/woopra/changelog/ x_refsource_CONFIRM
- http://www.exploit-db.com/exploits/24969 exploitx_refsource_EXPLOIT-DB
- http://www.openwall.com/lists/oss-security/2009/12/14/1 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2009/12/14/3 mailing-listx_refsource_MLIST
- http://www.osvdb.org/59051 vdb-entryx_refsource_OSVDB
- http://www.securityfocus.com/bid/37314 vdb-entryx_refsource_BIDExploit
- http://www.vupen.com/english/advisories/2009/2966 vdb-entryx_refsource_VUPENVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53825 vdb-entryx_refsource_XF
Change history (0)
No recorded changes yet.