CVE-2013-1744 describes a critical vulnerability in the IRIS citations management tool, specifically versions through 1.3, allowing remote attackers to execute arbitrary commands. With a CVSS score of 9.8, this vulnerability is easily exploitable over a network without authentication or user interaction, leading to complete compromise of confidentiality, integrity, and availability. While no active exploitation or Metasploit/Nuclei modules are reported, an ExploitDB entry for a similar preg_replace vulnerability in PHPWCMS suggests potential attack vectors, though community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3CPE matchmatch criteria | cpe:2.3:a:iris_citations_management_tool_project:iris_citations_management_tool:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.