CVE-2013-6041: Softaculous Webuzo

High severity, CVSS 7.5. EPSS: 3.6% chance of exploitation in the next 30 days.

index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in a SOFTCookies sid cookie within a login action.

Affected products

  • Softaculous Webuzo: up to and including 2.1.3; version 2.1.0 only; version 2.1.1 only; version 2.1.2 only

Published 2014-12-27. Last modified 2026-06-16.