Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w28c-prr6-33rc

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroupware before 14.1 beta allows remote authenticated administrators to execute arbitrary PHP code via crafted callback values to the call_user_func PHP function, as demonstrated using the newsettings[system] parameter. NOTE: this can be exploited by remote attackers by leveraging CVE-2014-2987.

EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroupware before 14.1 beta allows remote authenticated administrators to execute arbitrary PHP code via crafted callback values to the call_user_func PHP function, as demonstrated using the newsettings[system] parameter. NOTE: this can be exploited by remote attackers by leveraging CVE-2014-2987.

EPSS

Процентиль: 75%
0.00907
Низкий

Дефекты

CWE-94

Связанные уязвимости

nvd
больше 11 лет назад

EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroupware before 14.1 beta allows remote authenticated administrators to execute arbitrary PHP code via crafted callback values to the call_user_func PHP function, as demonstrated using the newsettings[system] parameter. NOTE: this can be exploited by remote attackers by leveraging CVE-2014-2987.

debian
больше 11 лет назад

EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Commu ...

EPSS

Процентиль: 75%
0.00907
Низкий

Дефекты

CWE-94