CVE-2011-5130

Haudenschilt Family Connections Cms - Code Injection

Title source: rule

Description

dev/less.php in Family Connections CMS (FCMS) 2.5.0 - 2.7.1, when register_globals is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the argv[1] parameter.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/18208
exploitdb WORKING POC VERIFIED
by mr_me · phpwebappsphp
https://www.exploit-db.com/exploits/18198
metasploit WORKING POC EXCELLENT
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/familycms_less_exec.rb

Scores

EPSS 0.7451
EPSS Percentile 98.9%

Details

CWE
CWE-94
Status published
Products (8)
haudenschilt/family_connections_cms 2.5.0
haudenschilt/family_connections_cms 2.5.1
haudenschilt/family_connections_cms 2.5.2
haudenschilt/family_connections_cms 2.5.3
haudenschilt/family_connections_cms 2.5.4
haudenschilt/family_connections_cms 2.6.0
haudenschilt/family_connections_cms 2.7.0
haudenschilt/family_connections_cms 2.7.1
Published Aug 30, 2012
Tracked Since Feb 18, 2026