CVE-2014-2294

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
17/04/2018
Last modified:
22/05/2018

Description

Open Web Analytics (OWA) before 1.5.7 allows remote attackers to conduct PHP object injection attacks via a crafted serialized object in the owa_event parameter to queue.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openwebanalytics:open_web_analytics:*:*:*:*:*:*:*:* 1.5.7 (excluding)