7.5
CVSSv2

CVE-2013-6041

Published: 27/12/2014 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

index.php in Softaculous Webuzo prior to 2.1.4 allows remote malicious users to execute arbitrary commands via shell metacharacters in a SOFTCookies sid cookie within a login action.

Vulnerable Product Search on Vulmon Subscribe to Product

softaculous webuzo

softaculous webuzo 2.1.1

softaculous webuzo 2.1.0

softaculous webuzo 2.1.2

Exploits

# Exploit Title: Webuzo Multiple Vulnerabilities # Date: 7 October 2013 # Exploit Author: Mahendra # Vendor Homepage: wwwwebuzocom # Software Link: downloadswebuzocom/vaphp # Version: 213, other version might be vulnerable # Tested on: CentOS release 62 (FINAL) # CVE : CVE-2013-6041, CVE-2013-6042, CVE-2013-6043 ------------------- ...