LotusCMS Router PHP Command Injection Exploit

Input passed via the "page" parameter to index.php is not properly sanitised in the "Router()" function in core/lib/router.php before being used in an "eval()" call. This can be exploited to execute arbitrary PHP code.
Exploit Platform
Exploit Type
Product Name