CVE-2011-10011

NONE
CVSS v3
CVSS v2
57.51% EPSS (exploit probability)
CWE-94CWE

Description

WeBid 1.0.2 contains a remote code injection vulnerability in the converter.php script, where unsanitized input in the to parameter of a POST request is written directly into includes/currencies.php. This allows unauthenticated attackers to inject arbitrary PHP code, resulting in persistent remote code execution when the modified script is accessed or included by the application.

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references