VULNERABILITY INTELLIGENCE

CVE-2011-4458

CVSS score6.8 MEDIUM
EPSS probability3.07%
CISA KEVNot currently listed
Published2012-06-04
Last modified2026-06-16
CVSS vectorAV:N/AC:M/Au:N/C:P/I:P/A:P

Description

Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabled, allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-5092 and CVE-2011-5093.

Weakness classification

  • CWE-94: Improper Control of Generation of Code ('Code Injection')

Primary references