cvelist/2014/1xxx/CVE-2014-1683.json

92 lines
3.1 KiB
JSON
Raw Normal View History

2017-10-16 12:31:07 -04:00
{
2019-03-18 00:55:16 +00:00
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2014-1683",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
2017-10-16 12:31:07 -04:00
{
2019-03-18 00:55:16 +00:00
"lang": "eng",
"value": "The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248-04, when the pid parameter is 4, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) name, (2) email, (3) subject, or (4) message parameter to index.php."
2017-10-16 12:31:07 -04:00
}
2019-03-18 00:55:16 +00:00
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "65129",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/65129"
},
{
"name": "20140123 Remote Command Injection Vulnerability in SkyBlueCanvas CMS",
"refsource": "FULLDISC",
"url": "http://seclists.org/fulldisclosure/2014/Jan/159"
},
{
"name": "http://packetstormsecurity.com/files/124948/SkyBlueCanvas-CMS-1.1-r248-03-Command-Injection.html",
"refsource": "MISC",
"url": "http://packetstormsecurity.com/files/124948/SkyBlueCanvas-CMS-1.1-r248-03-Command-Injection.html"
},
{
"name": "skybluecanvas-index-command-exec(90670)",
"refsource": "XF",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/90670"
},
{
"name": "31183",
"refsource": "EXPLOIT-DB",
"url": "http://www.exploit-db.com/exploits/31183"
},
{
"name": "31432",
"refsource": "EXPLOIT-DB",
"url": "http://www.exploit-db.com/exploits/31432"
},
{
"name": "56646",
"refsource": "SECUNIA",
"url": "http://secunia.com/advisories/56646"
}
]
}
}