CVE-2013-10037 Details
Description
An OS command injection vulnerability exists in WebTester version 5.x via the install2.php installation script. The parameters cpusername, cppassword, and cpdomain are passed directly to shell commands without sanitization. A remote unauthenticated attacker can exploit this flaw by sending a crafted HTTP POST request, resulting in arbitrary command execution on the underlying system with web server privileges.
A command injection vulnerability has been identified in Eppler Software WebTester version 5.x, specifically within the install2.php script. This vulnerability allows remote, unauthenticated attackers to execute arbitrary commands on the server with the privileges of the web server user. The issue arises because the cpusername, cppassword, and cpdomain parameters are passed to shell commands without proper sanitization. Exploitation involves sending a crafted HTTP POST request with one of these parameters, leading to unauthorized command execution on the underlying system.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 31, 2025CISA-ADP
Assessed Jul 31, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://advisories.checkpoint.com/defense/advisories/public/2014/cpai-2014-1620.html | [email protected] | Advisory |
| https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/webtester_exec.rb | [email protected] | ExploitSource Code |
| https://sourceforge.net/p/webtesteronline/bugs/3/ | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://www.exploit-db.com/exploits/29132 | [email protected] | Exploit |
| https://www.vulncheck.com/advisories/webtester-unauth-command-execution | [email protected] | AdvisoryExploit |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Eppler Software WebTester | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | CVE Modified | CISA-ADP |
| Jul 31, 2025 | New CVE Received | [email protected] |
Volerion