CVE-2011-0635

Simploo CMS < 1.7.1 - Authenticated PHP Code Injection via FTP-Server Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-0635. PoCs published by David Vieira-Kurz.

AI-analyzed exploit summary This exploit demonstrates a PHP code injection vulnerability in Simploo CMS Community Edition via the FTP-Server field. The injected code is written to a configuration file and executed when accessed, allowing remote code execution.

Description

Static code injection vulnerability in Simploo CMS 1.7.1 and earlier allows remote authenticated users to inject arbitrary PHP code into config/custom/base.ini.php via the ftpserver parameter (FTP-Server field) to the sicore/updates/optionssav operation for index.php.

Exploits (1)

exploitdb WORKING POC
by David Vieira-Kurz · textwebappsphp
https://www.exploit-db.com/exploits/16016

This exploit demonstrates a PHP code injection vulnerability in Simploo CMS Community Edition via the FTP-Server field. The injected code is written to a configuration file and executed when accessed, allowing remote code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Simploo CMS Community Edition 1.7.1 and prior
Auth required
Prerequisites: Write privileges in the application · Access to the admin panel
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/16016
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/45906
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/70487
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/515809/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42953
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/64826

Scores

EPSS 0.0192
EPSS Percentile 77.2%

Details

CWE
CWE-94
Status published
Products (6)
simploo/simploo_cms 1.2.0
simploo/simploo_cms 1.3.0
simploo/simploo_cms 1.5.0
simploo/simploo_cms 1.5.2
simploo/simploo_cms 1.7.0
simploo/simploo_cms < 1.7.1
Published Jan 22, 2011
Tracked Since Feb 18, 2026