CVE-2011-1513

high
Published 2011-11-04 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
8.5

Description

Static code injection vulnerability in install_.php in e107 CMS 0.7.24 and probably earlier versions, when the installation script is not removed, allows remote attackers to inject arbitrary PHP code into e107_config.php via a crafted MySQL server name.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-36252 webapps php verified
Matt Bergin ยท 2011-10-24

e107 0.7.24 - 'cmd' Remote Command Execution

Source code queued for fetch โ€” refresh in a moment.

Application impact

VendorProductVersionsFixed
e107e107{"endIncluding":"0.7.24"}
e107e1070.7
e107e1070.7.0
e107e1070.7.1
e107e1070.7.2
e107e1070.7.3
e107e1070.7.4
e107e1070.7.5
e107e1070.7.6
e107e1070.7.7
e107e1070.7.8
e107e1070.7.9
e107e1070.7.10
e107e1070.7.11
e107e1070.7.12
e107e1070.7.13
e107e1070.7.14
e107e1070.7.15
e107e1070.7.16
e107e1070.7.17
e107e1070.7.18
e107e1070.7.19
e107e1070.7.20
e107e1070.7.21
e107e1070.7.22
e107e1070.545
e107e1070.547
e107e1070.548
e107e1070.549
e107e1070.551
e107e1070.552
e107e1070.553
e107e1070.554
e107e1070.555
e107e1070.600
e107e1070.601
e107e1070.602
e107e1070.603
e107e1070.604
e107e1070.605
e107e1070.606
e107e1070.607
e107e1070.608
e107e1070.609
e107e1070.610
e107e1070.611
e107e1070.612
e107e1070.613
e107e1070.614
e107e1070.615
e107e1070.615a
e107e1070.616
e107e1070.617
e107e1070.6171
e107e1070.6172
e107e1070.6173
e107e1070.6174
e107e1070.6175

References

CWEs

CWE-78

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.