CVE-2017-11167: Finecms Project Finecms
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
FineCMS 2.1.0 allows remote attackers to execute arbitrary PHP code by using a URL Manager "Add Site" action to enter this code after a ', sequence in a domain name, as demonstrated by the ',phpinfo() input value.
Affected products
- Finecms Project Finecms: version 2.1.0 only
Published 2017-07-12. Last modified 2026-06-17.