Skip to content

CVE-2011-5274

The drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before 0.32.11 allows remote attackers to execute arbitrary commands via shell metacharacters in the dtcpkg_directory parameter in a do_install action to dtc/.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0080 (0.8%)
Percentile: 74.2%
EPSS: 2026-05-06

Affects

gplhost:domain_technologie_control

Technical description

The drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before 0.32.11 allows remote attackers to execute arbitrary commands via shell metacharacters in the dtcpkg_directory parameter in a do_install action to dtc/.

Published: 3/21/2014, 4:38:58 AM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam