LotusCMS 3.0 is susceptible to remote code execution via the Router () function. This is done by embedding PHP code in the 'page' parameter, which will be passed to a eval call and allow remote code execution.
        
        
        
 id: CVE-2011-0518
info:
  name: LotusCMS 3.0 - Remote Code Execution
  author: pikpikcu
  severity:
...