CVE-2013-10037 is a critical OS command injection vulnerability affecting WebTester version 5.x, specifically within the install2.php script. It allows remote, unauthenticated attackers to execute arbitrary commands on the underlying system with web server privileges due to unsanitized parameters (cpusername, cppassword, cpdomain) passed directly to shell commands. The vulnerability has a CVSS score of 9.3 (CRITICAL) and an EPSS score indicating high exploitability, with readily available exploit modules in Metasploit. While not listed in CISA KEV, it garners significant community discussion, suggesting active awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Eppler Software | WebTester | 5.0CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.