CVE-2012-10033 is a remote code execution vulnerability in Narcissus caused by improper input handling in its image configuration workflow. The vulnerable path is in backend.php, which fails to sanitize the POST-supplied release parameter before passing it to the configure_image() function. That function subsequently invokes PHP's passthru() with attacker-controlled input. Because the input is not properly neutralized before being used in an OS command context, an attacker can supply crafted data to inject and execute arbitrary system commands on the underlying host. Exploitation is performed through a crafted POST request and results in command execution in the security context of the web server process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (Ruby file) that exploits a remote code execution vulnerability (CVE-2012-10033) in the Narcissus web application's backend.php script. The vulnerability arises from improper handling of the 'release' POST parameter, which is passed unsanitized to a PHP passthru() call, allowing attackers to inject and execute arbitrary system commands. The module is weaponized and leverages Metasploit's payload system to deliver a variety of command-based payloads (e.g., reverse shell, bind shell) using the 'release' parameter. The main attack vector is a network-based HTTP POST request to the backend.php endpoint, typically located at /narcissus-master/backend.php, but configurable via the TARGETURI option. The exploit checks for vulnerability by sending a benign command and looking for its output in the response. If vulnerable, it sends the actual payload for code execution. The module is suitable for targeting Linux/Unix systems running the vulnerable Narcissus web application. The repository is structured as a single Ruby file compatible with the Metasploit framework, and all exploit logic is contained within this file.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.