Critical severityNVD Advisory· Published Aug 13, 2025· Updated Apr 15, 2026
CVE-2011-10011
CVE-2011-10011
Description
WeBid 1.0.2 contains a remote code injection vulnerability in the converter.php script, where unsanitized input in the to parameter of a POST request is written directly into includes/currencies.php. This allows unauthenticated attackers to inject arbitrary PHP code, resulting in persistent remote code execution when the modified script is accessed or included by the application.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/webid_converter.rbnvd
- sourceforge.net/projects/simpleauction/nvd
- web.archive.org/web/20121024110058/http://www.webidsupport.com/forums/showthread.phpnvd
- www.exploit-db.com/exploits/17487nvd
- www.exploit-db.com/exploits/18934nvd
- www.vulncheck.com/advisories/webid-remote-php-code-injectionnvd
News mentions
0No linked articles in our index yet.