Back to Database
Status published
High
CVE-2013-6041
index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to...
Vulnerability Description
index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in a SOFTCookies sid cookie within a login action.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-6041
Credits & Attribution
No credits recorded in the NVD database.
References
More from softaculous
View All →CVE-2025-9277
SiteSEO – SEO Simplified <= 1.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Broken Regex Expression
Medium
6.4
CVE-2025-4223
Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.0 - Reflected Cross-Site Scripting via login_url Parameter
Medium
4.7
CVE-2025-2104
Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.9 - Missing Authorization to Authenticated (Contributor+) Post Publication
Medium
4.3
CVE-2025-1926
Page Builder: Pagelayer – Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification
Medium
4.3
CVE-2025-13085
SiteSEO – SEO Simplified <= 1.3.2 - Insecure Direct Object Reference to Sensitive Post Meta Disclosure
Medium
4.3
Affected Vendor
softaculous
View all reports →Affected Software
webuzo
Vulnerable Versions:
0, 2.1.0, 2.1.1, 2.1.2
Timeline
Official Publish:
December 27th, 2014
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.