← Back to browse · API

CVE-2013-10037

Severity
CRITICAL
CVSS
9.3
EPSS
0.09615
Risk score
40.57
CISA KEV
No
PoC
No
Published
2025-07-31
Modified
2026-04-07
First seen
2026-08-07
Aliases
EUVD-2013-7250, GHSA-3W97-V426-7JW9
Products
Eppler Software:WebTester 5.0
Sources
euvd EUVD-2013-7250

Description

An OS command injection vulnerability exists in WebTester version 5.x via the install2.php installation script. The parameters cpusername, cppassword, and cpdomain are passed directly to shell commands without sanitization. A remote unauthenticated attacker can exploit this flaw by sending a crafted HTTP POST request, resulting in arbitrary command execution on the underlying system with web server privileges.

References