CVE-2012-5223

UnknownEPSS 40.53%

Last modified

CVE-2012-5223 is a vulnerability of currently unknown severity. The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" in the char_repl parameter, which is inserted into a regular expression that is processed by the preg_replace function with the eval switch.. EPSS estimates a 40.53% chance of exploitation in the next 30 days.

Description

The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" in the char_repl parameter, which is inserted into a regular expression that is processed by the preg_replace function with the eval switch.

Metrics

EPSS Probability
40.53%

98.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
CrawlabilityVbseo<= 3.6.0
CrawlabilityVbseo2.0.0
CrawlabilityVbseo2.1.0
CrawlabilityVbseo2.1.1
CrawlabilityVbseo2.2.0
CrawlabilityVbseo2.3.0
CrawlabilityVbseo2.4.0
CrawlabilityVbseo2.4.5
CrawlabilityVbseo3.0.0
CrawlabilityVbseo3.1.0
CrawlabilityVbseo3.2.0
CrawlabilityVbseo3.3.0
CrawlabilityVbseo3.3.1
CrawlabilityVbseo3.5.0
CrawlabilityVbseo3.5.1
CrawlabilityVbseo3.5.2
CrawlabilityVbseo3.6.0Beta1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-5223?
The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" in the char_repl parameter, which is inserted into a regular expression that is processed by the preg_replace function with the eval switch.
How severe is CVE-2012-5223?
Severity scoring for CVE-2012-5223 is pending analysis. The EPSS model estimates a 40.53% probability of exploitation in the next 30 days.
How do I fix CVE-2012-5223?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-5223?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST