9.3

CVE-2014-7178

Exploit
Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP function.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EnaleanTuleap Version <= 7.5.99.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.06% 0.912
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://www.tuleap.org/recent-vulnerabilities
Vendor Advisory
http://seclists.org/fulldisclosure/2014/Oct/121
Exploit
https://www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-7178/
Exploit