CVE-2011-5061: Code Injection
functions.php in WHMCompleteSolution (WHMCS) 4.0.x through 5.0.x allows remote attackers to trigger arbitrary code execution in the Smarty templating system by submitting a crafted ticket, related to improper handling of characters in the subject field.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-5061?
CVE-2011-5061 has been classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2011-5061?
To fix CVE-2011-5061, upgrade WHMCS to version 5.0.3 or later, which addresses the vulnerability.
What versions of WHMCS are affected by CVE-2011-5061?
CVE-2011-5061 affects WHMCS versions 4.0.x through 5.0.x, including several beta versions.
What are the risks associated with CVE-2011-5061?
The risks associated with CVE-2011-5061 include potential remote code execution and unauthorized access to sensitive data.
Is CVE-2011-5061 related to any other vulnerabilities?
CVE-2011-5061 is specifically related to issues in the Smarty templating system used within the WHMCS framework.