CVE-2014-8677
The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing database with a crafted name, or permissions to create arbitrary databases, or if PHP before 5.2 is being used, the configuration database is down, and smarty/templates_c is not writable to execute arbitrary php code via a crafted database name.
- Affected products
- Soplanning
- Soplanning
- ≤ 1.32
- Fix
- Available
- CVSS 3.0
- 5.3 MEDIUM
- EPSS
- 3.5% (88th percentile)
- Weakness
- CWE-284, CWE-94
- NVD status
- Modified
- Published
- 2017-08-31
CVE-2014-8677 at NVD
4 known exploits for CVE-2014-8677
Proof-of-concept code and exploit modules indexed by Sploitus