CVE-2012-5223: Code Injection
The procdeutf function in includes/functionsvbseocpabstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" in the charrepl parameter, which is inserted into a regular expression that is processed by the pregreplace function with the eval switch.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5223?
CVE-2012-5223 is considered to have a high severity due to the potential for remote code execution.
How do I fix CVE-2012-5223?
To fix CVE-2012-5223, upgrade to a patched version of vBSEO that addresses the vulnerability.
What software is affected by CVE-2012-5223?
CVE-2012-5223 affects vBSEO versions 3.5.0 through 3.6.0 and earlier.
Can CVE-2012-5223 lead to data compromise?
Yes, CVE-2012-5223 can lead to data compromise as it allows attackers to execute arbitrary PHP code.
Is there a known exploit for CVE-2012-5223?
Yes, there are known exploits for CVE-2012-5223 that demonstrate remote code execution attacks.