htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the hostname parameter.
References
Link | Resource |
---|---|
https://www.htbridge.com/advisory/HTB23198 | Exploit Third Party Advisory |
https://bugs.launchpad.net/eventum/+bug/1271499 | Exploit Issue Tracking Third Party Advisory |
http://bazaar.launchpad.net/~eventum-developers/eventum/trunk/revision/4665 | Patch Third Party Advisory |
http://www.securityfocus.com/archive/1/530891/100/0/threaded | Exploit Third Party Advisory VDB Entry |
Configurations
Information
Published : 2018-01-31 10:29
Updated : 2019-04-26 08:06
NVD link : CVE-2014-1632
Mitre link : CVE-2014-1632
JSON object : View
CWE
CWE-275
Permission Issues
Products Affected
eventum_project
- eventum