CVE-2011-5061

functions.php in WHMCompleteSolution (WHMCS) 4.0.x through 5.0.x allows remote attackers to trigger arbitrary code execution in the Smarty templating system by submitting a crafted ticket, related to improper handling of characters in the subject field.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
VendorProductVersion
whmcswhmcompletesolution
4.0.0
whmcswhmcompletesolution
4.0.1
whmcswhmcompletesolution
4.0.2
whmcswhmcompletesolution
4.1.0
whmcswhmcompletesolution
4.1.1
whmcswhmcompletesolution
4.1.2
whmcswhmcompletesolution
4.2.0
whmcswhmcompletesolution
4.2.0:beta_r1
whmcswhmcompletesolution
4.2.0:beta_r2
whmcswhmcompletesolution
4.2.0:beta_r3
whmcswhmcompletesolution
4.2.1
whmcswhmcompletesolution
4.3.0
whmcswhmcompletesolution
4.3.1
whmcswhmcompletesolution
4.4.0
whmcswhmcompletesolution
4.4.1
whmcswhmcompletesolution
4.4.2
whmcswhmcompletesolution
4.5.0
whmcswhmcompletesolution
4.5.1
whmcswhmcompletesolution
4.5.2
whmcswhmcompletesolution
5.0.0
whmcswhmcompletesolution
5.0.1
whmcswhmcompletesolution
5.0.2
whmcswhmcompletesolution
5.0.3
𝑥
= Vulnerable software versions