Lucene search

K
nvd[email protected]NVD:CVE-2014-8998
HistoryNov 20, 2014 - 1:55 p.m.

CVE-2014-8998

2014-11-2013:55:07
CWE-94
web.nvd.nist.gov

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.2 High

AI Score

Confidence

High

0.954 High

EPSS

Percentile

99.4%

lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a crafted HTTP header to index.php, which is processed by the preg_replace function with the eval switch.

Affected configurations

NVD
Node
x7chatx7_chatMatch2.0.0
OR
x7chatx7_chatMatch2.0.0a1
OR
x7chatx7_chatMatch2.0.0a2
OR
x7chatx7_chatMatch2.0.0a3
OR
x7chatx7_chatMatch2.0.0b1
OR
x7chatx7_chatMatch2.0.0b2
OR
x7chatx7_chatMatch2.0.1a1
OR
x7chatx7_chatMatch2.0.2
OR
x7chatx7_chatMatch2.0.3
OR
x7chatx7_chatMatch2.0.4
OR
x7chatx7_chatMatch2.0.4.1
OR
x7chatx7_chatMatch2.0.4.3
OR
x7chatx7_chatMatch2.0.4.4
OR
x7chatx7_chatMatch2.0.5
OR
x7chatx7_chatMatch2.0.5.1

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

7.2 High

AI Score

Confidence

High

0.954 High

EPSS

Percentile

99.4%

Related for NVD:CVE-2014-8998