CVE-2013-10051 | InstantCMS up to 1.6 HTTP GET Request eval look eval injection (EUVD-2013-7270 / EDB-26622)
A vulnerability was found in InstantCMS up to 1.6. It has been declared as critical. This affects the function eval of the component HTTP GET Request Handler. Executing manipulation of the argument look can lead to improper neutralization of directives in dynamically evaluated code.
This vulnerability is tracked as CVE-2013-10051. The attack can be launched remotely. Moreover, an exploit is present.