PHP Code Injection in PbootCMS Version 0.9.8
CVE-2018-10133

9.8CRITICAL

Key Information:

Vendor

Pbootcms

Status
Vendor
CVE Published:
16 April 2018

What is CVE-2018-10133?

PbootCMS version 0.9.8 is susceptible to PHP code injection due to improper handling of the IF label in certain files. Specifically, the vulnerability can be exploited via index.php/About/6.html or admin.php/Site/index.html, where the parserIfLabel function in apps/home/controller/ParserController.php is compromised, allowing malicious input to be executed. This flaw poses serious risks for web applications using this version of PbootCMS, highlighting the necessity for immediate updates and patching to secure user data and application integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.