CVE-2013-6041
Softaculous Webuzo < 2.1.4 - Remote Code Execution via SOFTCookies sid Cookie
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-6041.
AI-analyzed exploit summary The exploit demonstrates a remote OS command injection vulnerability in Webuzo 2.1.3 via cookie manipulation, allowing arbitrary command execution without authentication. It also includes proof-of-concept payloads for XSS and username enumeration vulnerabilities.
Description
index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in a SOFTCookies sid cookie within a login action.
Exploits (1)
The exploit demonstrates a remote OS command injection vulnerability in Webuzo 2.1.3 via cookie manipulation, allowing arbitrary command execution without authentication. It also includes proof-of-concept payloads for XSS and username enumeration vulnerabilities.