CVE-2014-2302
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
19/07/2018
Last modified:
18/09/2018
Description
The installer script in webEdition CMS before 6.2.7-s1 and 6.3.x before 6.3.8-s1 allows remote attackers to conduct PHP Object Injection attacks by intercepting a request to update.webedition.org.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:webedition:webedition_cms:*:*:*:*:*:*:*:* | 6.2.7.0 (excluding) | |
| cpe:2.3:a:webedition:webedition_cms:*:*:*:*:*:*:*:* | 6.3.0 (including) | 6.3.8 (excluding) |
| cpe:2.3:a:webedition:webedition_cms:6.2.7.0:s1:*:*:*:*:*:* | ||
| cpe:2.3:a:webedition:webedition_cms:6.3.8:s1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://packetstormsecurity.com/files/126861/webEdition-CMS-2.8.0.0-Remote-Command-Execution.html
- http://seclists.org/fulldisclosure/2014/May/147
- http://www.securityfocus.com/archive/1/532230/100/0/threaded
- http://www.securityfocus.com/bid/67692
- https://www.redteam-pentesting.de/advisories/rt-sa-2014-004



