CVE-2013-1668: Coscms
High severity, CVSS 8.5. EPSS: 7% chance of exploitation in the next 30 days.
The uploadFile function in upload/index.php in CosCMS before 1.822 allows remote administrators to execute arbitrary commands via shell metacharacters in the name of an uploaded file.
Affected products
- Coscms Coscms: up to and including 1.721; version 1.3 only; version 1.41 only
Published 2014-05-23. Last modified 2026-06-16.