CVE-2017-11167: Finecms Project Finecms

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

FineCMS 2.1.0 allows remote attackers to execute arbitrary PHP code by using a URL Manager "Add Site" action to enter this code after a ', sequence in a domain name, as demonstrated by the ',phpinfo() input value.

Affected products

Published 2017-07-12. Last modified 2026-06-17.