PoC Index

CVE-2011-4337

HIGH 7.5EPSS 2.6%

Static code injection vulnerability in translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to inject arbitrary PHP code into an executable language file in the i18n directory via the lang variable.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
2.60% chance of exploitation in the next 30 days, 84th percentile
Published
2012-01-29
Updated
2024-09-17

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related