Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2013-7250 | An OS command injection vulnerability exists in WebTester version 5.x via the install2.php installation script. The parameters cpusername, cppassword, and cpdomain are passed directly to shell commands without sanitization. A remote unauthenticated attacker can exploit this flaw by sending a crafted HTTP POST request, resulting in arbitrary command execution on the underlying system with web server privileges. |
Thu, 31 Jul 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eppler Software
Eppler Software webtester Webtester Webtester webtester |
|
| Vendors & Products |
Eppler Software
Eppler Software webtester Webtester Webtester webtester |
Thu, 31 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 31 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An OS command injection vulnerability exists in WebTester version 5.x via the install2.php installation script. The parameters cpusername, cppassword, and cpdomain are passed directly to shell commands without sanitization. A remote unauthenticated attacker can exploit this flaw by sending a crafted HTTP POST request, resulting in arbitrary command execution on the underlying system with web server privileges. | |
| Title | WebTester 5.x install2.php Unauthenticated Command Execution | |
| Weaknesses | CWE-78 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-07T14:02:59.797Z
Reserved: 2025-07-30T16:27:28.910Z
Link: CVE-2013-10037
Updated: 2025-07-31T15:23:47.643Z
Status : Deferred
Published: 2025-07-31T15:15:33.417
Modified: 2026-04-15T00:35:42.020
Link: CVE-2013-10037
No data.
OpenCVE Enrichment
Updated: 2025-07-31T20:20:39Z
EUVD