EGroupware 'unserialize()' Multiple Arbitrary File Deletion Vulnerabilities
BID:65651
Info
EGroupware 'unserialize()' Multiple Arbitrary File Deletion Vulnerabilities
| Bugtraq ID: | 65651 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2027 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 19 2014 12:00AM |
| Updated: | Feb 20 2014 01:52PM |
| Credit: | Pedro Ribeiro |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
EGroupware 'unserialize()' Multiple Arbitrary File Deletion Vulnerabilities
EGroupware is prone to multiple arbitrary-file-deletion vulnerabilities.
Successfully exploiting these issues will allow attackers to delete arbitrary files in the context of the application.
EGroupware 1.8.005 is vulnerable; other versions may also be affected.
EGroupware is prone to multiple arbitrary-file-deletion vulnerabilities.
Successfully exploiting these issues will allow attackers to delete arbitrary files in the context of the application.
EGroupware 1.8.005 is vulnerable; other versions may also be affected.
Exploit / POC
EGroupware 'unserialize()' Multiple Arbitrary File Deletion Vulnerabilities
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
EGroupware 'unserialize()' Multiple Arbitrary File Deletion Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
EGroupware 'unserialize()' Multiple PHP Code Execution Vulnerabilities
References:
References:
- eGroupware Homepage (eGroupware)