CVE-2012-6554
43Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 17%
from disclosure to weapon0 days
Published on NVDMay 23
1st PoCMay 19
metasploitMay 30
exploitation probability
17%top 3% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
functions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute arbitrary PHP code via the message[message_text] parameter to chat/add_messag, which is not properly handled when executing the preg_replace function with the eval switch.
Affected products
n/a · n/apublic PoCs found — 2
cve_referencewww.exploit-db.com/exploits/18898unverifiedexploitdbwww.exploit-db.com/exploits/18898unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.