eGroupWare 'call_user_func()' Function Remote Code Execution Vulnerability
BID:67409
Info
eGroupWare 'call_user_func()' Function Remote Code Execution Vulnerability
| Bugtraq ID: | 67409 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2988 |
| Remote: | Yes |
| Local: | No |
| Published: | May 06 2014 12:00AM |
| Updated: | May 19 2014 01:54AM |
| Credit: | High-Tech Bridge Security Research Lab |
| Vulnerable: |
eGroupWare eGroupWare 1.8.4 20120405 eGroupWare eGroupWare 1.8.1 20110421 |
| Not Vulnerable: | |
Discussion
eGroupWare 'call_user_func()' Function Remote Code Execution Vulnerability
eGroupWare is prone to a remote code-execution vulnerability because it fails to properly sanitize the user-supplied input.
A remote attacker with administrative privileges can leverage this issue to execute arbitrary code within the context of the application.
Versions prior to eGroupWare 1.8.007.20140506 are vulnerable.
eGroupWare is prone to a remote code-execution vulnerability because it fails to properly sanitize the user-supplied input.
A remote attacker with administrative privileges can leverage this issue to execute arbitrary code within the context of the application.
Versions prior to eGroupWare 1.8.007.20140506 are vulnerable.
Exploit / POC
eGroupWare 'call_user_func()' Function Remote Code Execution Vulnerability
The following example data is available:
The following example data is available:
Solution / Fix
eGroupWare 'call_user_func()' Function Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
eGroupWare 'call_user_func()' Function Remote Code Execution Vulnerability
References:
References:
- eGroupWare Homepage (eGroupWare)