CVE Feed

    Dashboard / CVE / CVE-2011-10011

    CVE-2011-10011

    WeBid 1.0.2 contains a remote code injection vulnerability in the converter.php script, where unsanitized input in the to parameter of a POST request is written directly into includes/currencies.php. This allows unauthenticated attackers to inject arbitrary PHP code, resulting in persistent remote code execution when the modified script is accessed or included by the application.

    Published:Aug 13, 2025
    Last Modified:Apr 15, 2026
    EPS:Aug 13, 2025
    EPSS Score:0.53506
    CVSS Score:10

    Affected Products

    Vendor
    Webidsupport
    Product
    Webid

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High