X2CRM 'ProfileController.php' CVE-2014-2664 Arbitrary File Upload Vulnerability
BID:66506
CVE-2014-2664 |Info
X2CRM 'ProfileController.php' CVE-2014-2664 Arbitrary File Upload Vulnerability
| Bugtraq ID: | 66506 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2664 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 20 2014 12:00AM |
| Updated: | Mar 20 2014 12:00AM |
| Credit: | Egidio Romano, Secunia Research. |
| Vulnerable: |
X2Engine X2CRM 3.7.5 X2Engine X2CRM 3.7.4 X2Engine X2CRM 3.7.3 |
| Not Vulnerable: |
X2Engine X2CRM 4.0 |
Exploit / POC
X2CRM 'ProfileController.php' CVE-2014-2664 Arbitrary File Upload Vulnerability
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
References
X2CRM 'ProfileController.php' CVE-2014-2664 Arbitrary File Upload Vulnerability
References:
References:
- Multiple vulnerabilities in X2Engine (x2community)
- X2Engine 4.0 Highlights (x2community)