Sploitus

CVE-2014-7985

2 known exploits for CVE-2014-7985

Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter to install/index.php.

Affected products
Espocrm
Espocrm
≤ 2.5.2
Fix
Available
CVSS 2.0
10.0 HIGH
EPSS
5.0% (92th percentile)
Weakness
CWE-22
NVD status
Modified
Published
2014-10-31
CVE-2014-7985 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2014-7985

Proof-of-concept code and exploit modules indexed by Sploitus