CVE-2014-1683

Scores

EPSS

0.785medium78.5%
0%20%40%60%80%100%

Percentile: 78.5%

CVSS

6.8medium2.0
0246810

CVSS Score: 6.8/10

All CVSS Scores

CVSS 2.0
6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Description

The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248-04, when the pid parameter is 4, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) name, (2) email, (3) subject, or (4) message parameter to index.php.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-134

Exploits

Exploit ID: 31183

Source: exploitdb

URL: https://www.exploit-db.com/exploits/31183

Exploit ID: 31432

Source: exploitdb

URL: https://www.exploit-db.com/exploits/31432

Vulnerable Software (1)

Type: Configuration

Vendor: skybluecanvas

Product: skybluecanvas

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:skybluecanvas:skybluecanvas:*:*:*:*:*:*:*:*",      "versionEndIncluding": "1.1_r248-03",      "vulnerable": true    }  ],  "operator": "OR"}

Source: nvd