216.73.217.22

CVE-2013-10051

· Published 01/08/2025 21:15 · Modified 01/08/2025 21:15

Labels: CVE-2013-10051 2025-08-01CVE-2013-10051CWE-95[email protected]

Essential information

Published
01/08/2025 21:15
Modified
01/08/2025 21:15
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A remote PHP code execution vulnerability exists in InstantCMS version 1.6 and earlier due to unsafe use of eval() within the search view handler. Specifically, user-supplied input passed via the look parameter is concatenated into a PHP expression and executed without proper sanitation. A remote attacker can exploit this flaw by sending a crafted HTTP GET request with a base64-encoded payload in the Cmd header, resulting in arbitrary PHP code execution within the context of the web server.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
instantcms / instantcms cpe:2.3:a:instantcms:instantcms:<1.6:*:*:*:*:*:*:*

References