Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2024-51180 | A vulnerability classified as critical has been found in FoxCMS up to 1.2. Affected is an unknown function of the file /install/installdb.php of the component Configuration File Handler. The manipulation of the argument database password leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Tue, 15 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Qianfox
         Qianfox foxcms  | 
|
| CPEs | cpe:2.3:a:qianfox:foxcms:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Qianfox
         Qianfox foxcms  | 
Tue, 24 Dec 2024 03:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Mon, 23 Dec 2024 01:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A vulnerability classified as critical has been found in FoxCMS up to 1.2. Affected is an unknown function of the file /install/installdb.php of the component Configuration File Handler. The manipulation of the argument database password leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Title | FoxCMS Configuration File installdb.php code injection | |
| Weaknesses | CWE-74 CWE-94  | 
|
| References | 
         | |
| Metrics | 
        
        cvssV2_0
         
 
 
 
  | 
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-12-24T02:05:11.393Z
Reserved: 2024-12-22T16:47:38.979Z
Link: CVE-2024-12900
Updated: 2024-12-24T02:04:53.068Z
Status : Analyzed
Published: 2024-12-23T02:15:05.630
Modified: 2025-07-15T20:08:35.187
Link: CVE-2024-12900
No data.
                        OpenCVE Enrichment
                    Updated: 2025-07-12T16:01:36Z
 EUVD