CVE-2011-1513: OS Command Injection
Static code injection vulnerability in install.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to inject arbitrary PHP code into e107config.php via a crafted MySQL server name.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1513?
CVE-2011-1513 is classified as a high-severity vulnerability due to its potential to allow arbitrary PHP code execution.
How do I fix CVE-2011-1513?
To fix CVE-2011-1513, ensure that the install_.php file is removed after installation of the affected e107 CMS versions.
Which versions of e107 CMS are affected by CVE-2011-1513?
CVE-2011-1513 affects e107 CMS versions up to and including 0.7.24 and possibly earlier versions.
Can CVE-2011-1513 be exploited remotely?
Yes, CVE-2011-1513 can be remotely exploited by attackers to inject malicious PHP code into the system.
What are the potential impacts of CVE-2011-1513?
The potential impacts of CVE-2011-1513 include unauthorized access, data compromise, and complete system control from remote attackers.