CVE-2018-10133: Code Injection
Published Apr 16, 2018
·Updated
PbootCMS v0.9.8 allows PHP code injection via an IF label in index.php/About/6.html or admin.php/Site/index.html, related to the parserIfLabel function in \apps\home\controller\ParserController.php.
Affected Software
1 affected component
Pbootcms Pbootcms=0.9.8
Event History
Apr 16, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-10133?
CVE-2018-10133 is a vulnerability in PbootCMS v0.9.8 that allows PHP code injection via an IF label in specific URLs.
2
How severe is CVE-2018-10133?
CVE-2018-10133 has a severity rating of critical with a CVSS score of 9.8.
3
How does CVE-2018-10133 affect PbootCMS?
CVE-2018-10133 affects PbootCMS version 0.9.8.
4
How can CVE-2018-10133 be exploited?
CVE-2018-10133 can be exploited by injecting PHP code through an IF label in specific URLs.
5
Is there a fix available for CVE-2018-10133?
There may be patches or updates available for PbootCMS v0.9.8 to mitigate the vulnerability. It is recommended to check with the vendor for the latest security updates.