CVE-2014-2027

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
31/03/2015
Last modified:
12/04/2025

Description

eGroupware before 1.8.006.20140217 allows remote attackers to conduct PHP object injection attacks, delete arbitrary files, and possibly execute arbitrary code via the (1) addr_fields or (2) trans parameter to addressbook/csv_import.php, (3) cal_fields or (4) trans parameter to calendar/csv_import.php, (5) info_fields or (6) trans parameter to csv_import.php in (a) projectmanager/ or (b) infolog/, or (7) processed parameter to preferences/inc/class.uiaclprefs.inc.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:egroupware:egroupware:*:*:*:*:*:*:*:* 1.8006 (including)