CVE-2014-2988
N/A
N/A
Summary
EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroupware before 14.1 beta allows remote authenticated administrators to execute arbitrary PHP code via crafted callback values to the call_user_func PHP function, as demonstrated using the newsettings[system] parameter. NOTE: this can be exploited by remote attackers by leveraging CVE-2014-2987.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://advisories.mageia.org/MGASA-2014-0221.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:087
- https://www.htbridge.com/advisory/HTB23212
- http://www.securityfocus.com/archive/1/532103/100/0/threaded
References
- http://advisories.mageia.org/MGASA-2014-0221.html
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:087
- https://www.htbridge.com/advisory/HTB23212
- http://www.securityfocus.com/archive/1/532103/100/0/threaded
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.