Unrated severityNVD Advisory· Published May 23, 2014· Updated May 6, 2026
CVE-2013-1668
CVE-2013-1668
Description
The uploadFile function in upload/index.php in CosCMS before 1.822 allows remote administrators to execute arbitrary commands via shell metacharacters in the name of an uploaded file.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.exploit-db.com/exploits/24629nvdExploit
- www.securityfocus.com/bid/58332nvdExploit
- archives.neohapsis.com/archives/bugtraq/2013-03/0033.htmlnvd
- osvdb.org/90927nvd
- www.coscms.org/blog/view/4/Version-1.822nvd
- github.com/diversen/gallery/commit/7d58f870e8edc6597485dd1b80ea9fb78580190cnvd
- www.htbridge.com/advisory/HTB23145nvd
News mentions
0No linked articles in our index yet.