6.5
CVE-2012-6554
- EPSS 65.52%
- Veröffentlicht 23.05.2013 15:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
functions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute arbitrary PHP code via the message[message_text] parameter to chat/add_messag, which is not properly handled when executing the preg_replace function with the eval switch.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
A51dev ≫ Activecollab Chat Module Version1.0
A51dev ≫ Activecollab Chat Module Version1.1
A51dev ≫ Activecollab Chat Module Version1.1.1
A51dev ≫ Activecollab Chat Module Version1.2
A51dev ≫ Activecollab Chat Module Version1.3
A51dev ≫ Activecollab Chat Module Version1.3.2
A51dev ≫ Activecollab Chat Module Version1.4
A51dev ≫ Activecollab Chat Module Version1.4.1
A51dev ≫ Activecollab Chat Module Version1.5
A51dev ≫ Activecollab Chat Module Version1.5.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 65.52% | 0.983 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.