CVE-2013-6041: OS Command Injection
Published Dec 27, 2014
·Updated
index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in a SOFTCookies sid cookie within a login action.
Affected Software
4 affected components
Softaculous Webuzo<=2.1.3
Softaculous Webuzo=2.1.0
Softaculous Webuzo=2.1.1
Softaculous Webuzo=2.1.2
Event History
Dec 27, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-6041?
CVE-2013-6041 is considered a high severity vulnerability due to its potential to allow remote command execution.
2
How do I fix CVE-2013-6041?
To fix CVE-2013-6041, you should upgrade Webuzo to version 2.1.4 or later.
3
What software versions are affected by CVE-2013-6041?
CVE-2013-6041 affects Webuzo versions 2.1.0 to 2.1.3 inclusive.
4
Can CVE-2013-6041 be exploited without authentication?
Yes, CVE-2013-6041 can be exploited during the login action if the attacker manipulates the cookies.
5
What type of attacks can be performed using CVE-2013-6041?
CVE-2013-6041 allows attackers to execute arbitrary commands on the server, posing risks of data compromise.