LotusCMS 3.0 is susceptible to remote code execution via the Router () function. This is done by embedding PHP code in the 'page' parameter, which will be passed to a eval call and allow remote code execution.
id: CVE-2011-0518
info:
name: LotusCMS 3.0 - Remote Code Execution
author: pikpikcu
severity:
...