This allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" in the char_repl parameter, which is inserted into a regular expression that is processed by the preg_replace function with the eval switch.
Vulnerable Systems:
* Crawlability Vbseo 3.6.0 and prior
vBSEO could allow a remote attacker to execute arbitrary code on the system, caused by an error in the proc_deutf() function by functions_vbseocp_abstract.php script. An attacker could exploit this vulnerability using a specially-crafted request to execute arbitrary code on the vulnerable system.
Vendor Status:
Vendor had issued an update for this Vulnerability.