CVE-2013-10070 - CVE House
Back to Database
Status published Critical CVE-2013-10070

PHP-Charts v1.0 PHP Code Execution

Vulnerability Description

PHP-Charts v1.0 contains a PHP code execution vulnerability in wizard/url.php, where user-supplied GET parameter names are passed directly to eval() without sanitization. A remote attacker can exploit this flaw by crafting a request that injects arbitrary PHP code, resulting in command execution under the web server's context. The vulnerability allows unauthenticated attackers to execute system-level commands via base64-encoded payloads embedded in parameter names, leading to full compromise of the host system.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-10070

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • AkaStep

Affected Vendor

Affected Software

PHP-Charts
Vulnerable Versions:
1.0

Timeline

Official Publish: August 5th, 2025
Last Modified: April 7th, 2026
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.