peter bassill · operator
$ cve CVE-2013-1349 JSON

CVE-2013-1349 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 22.7% (pctl 98)

Patch early

A public exploit exists.

Description

Eval injection vulnerability in ajax.php in openSIS 4.5 through 5.2 allows remote attackers to execute arbitrary PHP code via the modname parameter.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS22.72% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2013-12-09
Last modified2026-06-16

Affected (1)

VendorProduct
os4edopensis

Public exploits

SourceTitleDate
exploit-dbOpenSIS 'modname' - PHP Code Execution (Metasploit)2013-12-24

References

→ the Explorer  ·  watch your stack  ·  NVD