Critical severity9.8NVD Advisory· Published Aug 1, 2025· Updated Jun 16, 2026
CVE-2013-10051
CVE-2013-10051
Description
A remote PHP code execution vulnerability exists in InstantCMS version 1.6 and earlier due to unsafe use of eval() within the search view handler. Specifically, user-supplied input passed via the look parameter is concatenated into a PHP expression and executed without proper sanitation. A remote attacker can exploit this flaw by sending a crafted HTTP GET request with a base64-encoded payload in the Cmd header, resulting in arbitrary PHP code execution within the context of the web server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:instantcms:instantcms:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:instantcms:instantcms:*:*:*:*:*:*:*:*range: <=1.6.0
- (no CPE)range: <=1.6
- (no CPE)range: *
Patches
Vulnerability mechanics
References
4- www.exploit-db.com/exploits/26622nvdExploit
- packetstorm.news/files/id/122176nvdThird Party Advisory
- raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/instantcms_exec.rbnvdThird Party Advisory
- www.vulncheck.com/advisories/instantcms-remote-php-code-executionnvdThird Party Advisory
News mentions
0No linked articles in our index yet.