WeBid 1.0.2 converter.php Remote PHP Code Injection
Vulnerability Description
WeBid 1.0.2 contains a remote code injection vulnerability in the converter.php script, where unsanitized input in the to parameter of a POST request is written directly into includes/currencies.php. This allows unauthenticated attackers to inject arbitrary PHP code, resulting in persistent remote code execution when the modified script is accessed or included by the application.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2011-10011
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- EgiX
References
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/webid_converter.rb
- https://www.exploit-db.com/exploits/17487
- https://www.exploit-db.com/exploits/18934
- https://web.archive.org/web/20121024110058/http://www.webidsupport.com/forums/showthread.php?3892
- https://sourceforge.net/projects/simpleauction/
- https://www.vulncheck.com/advisories/webid-remote-php-code-injection
Affected Vendor
WeBid
View all reports →