Arbitrary Code Execution in WHMCompleteSolution (WHMCS) via Crafted Ticket Subject Field

Arbitrary Code Execution in WHMCompleteSolution (WHMCS) via Crafted Ticket Subject Field

CVE-2011-5061 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

functions.php in WHMCompleteSolution (WHMCS) 4.0.x through 5.0.x allows remote attackers to trigger arbitrary code execution in the Smarty templating system by submitting a crafted ticket, related to improper handling of characters in the subject field.

Learn more about our Web Application Penetration Testing UK.