vendor:
ValidForm Builder
by:
HackeR aRaR
9,3
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: ValidForm Builder
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: YES
Related CWE: N/A
CPE: //a:validformbuilder:validformbuilder:1.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2010
ValidForm Builder script Remote Command Execution
A vulnerability exists in the ValidForm Builder script, which allows an attacker to execute arbitrary commands on the vulnerable system. The vulnerability is due to insufficient sanitization of user-supplied input in the 'shell_exec' function in the 'class.phpcaptcha.php' file. An attacker can exploit this vulnerability by sending a malicious HTTP request to the vulnerable script. Successful exploitation of this vulnerability can result in arbitrary command execution on the vulnerable system.
Mitigation:
Upgrade to the latest version of ValidForm Builder script.