S4E just found a high top 10 tcp port service scan
critical·Web Vulnerabilities·Updated Oct 15, 2025

CVE-2011-0518 Scanner

CVE-2011-0518 Scanner - Remote Code Execution vulnerability in LotusCMS

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2011-0518
5.1
CVSS

Directory traversal vulnerability in core/lib/router.php in LotusCMS Fraise 3.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via the system parameter to index.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 5, 2026View on NVD →
Detail

LotusCMS is a content management system used widely by various organizations for managing web content. It's favored for its flexibility and ease of integration across different platforms. Many small to medium-sized businesses use LotusCMS due to its open-source nature, allowing customization and scalability. Web developers and content creators leverage its user-friendly interface to design and manage websites efficiently. The community support and rich documentation make it a popular choice among developers seeking a robust CMS solution. LotusCMS enables dynamic content handling, ensuring active online presence for users.

The Remote Code Execution vulnerability in LotusCMS 3.0 allows attackers to execute arbitrary code on the server. It's a severe security flaw that lets malicious actors inject PHP code through certain parameters. The vulnerability arises primarily due to improper input validation. This security issue can be exploited over a network without needing an authenticated session. Such vulnerabilities pose significant risks, as they can lead to unauthorized control over the affected systems. Addressing them promptly is critical to protect sensitive data and resources.

The vulnerability resides in the 'Router' function, which improperly evaluates user inputs. Specifically, the 'page' parameter, if unfiltered, becomes a conduit for executing harmful PHP code. Attackers craft payloads that, when embedded, are executed as part of a system function call. This issue stems from lack of adequate sanitation and validation of input data. Exploits target the 'eval' function, which evaluates code and allows remote code execution. As a result, attackers can control the server, leading to extensive breaches.

If exploited, this vulnerability can lead to complete system compromise. Malicious actors may gain access to sensitive data and modify or delete website content. It can be used to install backdoors, leading to persistent threats. Organizations may face data breaches, loss of customer trust, and potential legal consequences. Denial of service (DoS) conditions can also result from unauthorized traffic redirecting efforts. The impact is pervasive, affecting operational integrity and data confidentiality.

REFERENCES

Solution Advice
  • Apply the latest software patch and updates provided by LotusCMS to address the vulnerability.
  • Implement input validation and sanitation to prevent code injection through parameters.
  • Limit access permissions to the application, allowing only trusted users to make changes.
  • Conduct regular code reviews and security audits to identify potential vulnerabilities.
  • Consider isolation of the web server using the principle of least privilege.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.