6.8
CVE-2014-1683
- EPSS 31.42%
- Veröffentlicht 29.01.2014 18:55:27
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248-04, when the pid parameter is 4, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) name, (2) email, (3) subject, or (4) message parameter to index.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Skybluecanvas ≫ Skybluecanvas Version <= 1.1_r248-03
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 31.42% | 0.981 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-134 Use of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
http://packetstormsecurity.com/files/124948/SkyBlueCanvas-CMS-1.1-r248-03-Command-Injection.html
http://seclists.org/fulldisclosure/2014/Jan/159
http://secunia.com/advisories/56646
http://www.exploit-db.com/exploits/31183
http://www.exploit-db.com/exploits/31432
http://www.securityfocus.com/bid/65129
https://exchange.xforce.ibmcloud.com/vulnerabilities/90670