VULNERABILITY INTELLIGENCE
CVE-2011-4458
CVSS score6.8 MEDIUM
EPSS probability3.07%
CISA KEVNot currently listed
Published2012-06-04
Last modified2026-06-16
CVSS vectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Description
Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabled, allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-5092 and CVE-2011-5093.
Weakness classification
- CWE-94: Improper Control of Generation of Code ('Code Injection')
Primary references
- cve@mitre.org — Patch, Vendor Advisory
- cve@mitre.org — Patch, Vendor Advisory
- cve@mitre.org — Patch, Vendor Advisory
- cve@mitre.org
- cve@mitre.org
- af854a3a-2127-422b-91ae-364da2661108 — Patch, Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Patch, Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Patch, Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108
- af854a3a-2127-422b-91ae-364da2661108