CVE-2011-5130
Haudenschilt Family Connections Cms - Code Injection
Title source: ruleDescription
dev/less.php in Family Connections CMS (FCMS) 2.5.0 - 2.7.1, when register_globals is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the argv[1] parameter.
Exploits (3)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/18208
metasploit
WORKING POC
EXCELLENT
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/familycms_less_exec.rb
References (7)
Scores
EPSS
0.7451
EPSS Percentile
98.9%
Details
CWE
CWE-94
Status
published
Products (8)
haudenschilt/family_connections_cms
2.5.0
haudenschilt/family_connections_cms
2.5.1
haudenschilt/family_connections_cms
2.5.2
haudenschilt/family_connections_cms
2.5.3
haudenschilt/family_connections_cms
2.5.4
haudenschilt/family_connections_cms
2.6.0
haudenschilt/family_connections_cms
2.7.0
haudenschilt/family_connections_cms
2.7.1
Published
Aug 30, 2012
Tracked Since
Feb 18, 2026