CVE-2016-1000031

Executive Summary

Apache Commons FileUpload versions prior to 1.3.3 allow attackers to manipulate DiskFileItem objects via crafted file uploads, leading to arbitrary code execution on the server. The flaw arises from insufficient validation of file paths and names, enabling path traversal and execution of malicious payloads. Exploitation requires access to the upload endpoint, potentially compromising the entire application stack.


Authoritative CVE Metadata - CVSS Base Score: 9.8 (CRITICAL) - Published: 2016-10-25T14:29:00.180 - Last Modified: 2026-10-07T19:17:10.767

Original Description: Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution

"Without this playing with fantasy no creative work has ever yet come to birth. The debt we owe to the play of the imagination is incalculable."

— Carl Jung
Source: NVD