CVE-2013-4879
BigTree CMS <4.0 RC2 - SQL Injection
Title source: llmDescription
SQL injection vulnerability in core/inc/bigtree/cms.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to index.php.
Exploits (1)
Scores
EPSS
0.0111
EPSS Percentile
78.2%
Details
CWE
CWE-89
Status
published
Products (2)
bigtreecms/bigtree_cms
4.0 b1 (8 CPE variants)
bigtreecms/bigtree_cms
< 4.0
Published
Aug 14, 2013
Tracked Since
Feb 18, 2026