Логотип exploitDog
bind:CVE-2014-2268
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2014-2268

Количество 2

Количество 2

nvd логотип

CVE-2014-2268

около 11 лет назад

views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-install the application via a request that sets the X-Requested-With HTTP header, as demonstrated by executing arbitrary PHP code via the db_name parameter.

CVSS2: 5
EPSS: Высокий
github логотип

GHSA-j3m9-x2hx-qg5v

больше 3 лет назад

views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-install the application via a request that sets the X-Requested-With HTTP header, as demonstrated by executing arbitrary PHP code via the db_name parameter.

EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2014-2268

views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-install the application via a request that sets the X-Requested-With HTTP header, as demonstrated by executing arbitrary PHP code via the db_name parameter.

CVSS2: 5
77%
Высокий
около 11 лет назад
github логотип
GHSA-j3m9-x2hx-qg5v

views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-install the application via a request that sets the X-Requested-With HTTP header, as demonstrated by executing arbitrary PHP code via the db_name parameter.

77%
Высокий
больше 3 лет назад

Уязвимостей на страницу