CVE-2012-5777
Eval injection vulnerability in the ReplaceListVars function in the template parser in e/class/connect.php in EmpireCMS 6.6 allows user-assisted remote attackers to execute arbitrary PHP code via a crafted template.
- Affected products
- Empirecms
- Phome Empirecms
- = 6.6
- Fix
- Available
- CVSS 2.0
- 6.8 MEDIUM
- EPSS
- 2.2% (81th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2012-11-16
CVE-2012-5777 at NVD
2 known exploits for CVE-2012-5777
Proof-of-concept code and exploit modules indexed by Sploitus