Enalean Tuleap 'svn/viewvc.php' Remote Command Execution Vulnerability
BID:70769
Info
Enalean Tuleap 'svn/viewvc.php' Remote Command Execution Vulnerability
| Bugtraq ID: | 70769 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-7178 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 28 2014 12:00AM |
| Updated: | Oct 28 2014 12:00AM |
| Credit: | Jerzy Kramarz |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Enalean Tuleap 'svn/viewvc.php' Remote Command Execution Vulnerability
Enalean Tuleap is prone to a remote command-execution vulnerability because the application fails to sufficiently sanitize input data.
An attacker may leverage this issue to execute arbitrary commands in the context of the affected application.
Enalean Tuleap 7.4.99.5 and prior are vulnerable.
Enalean Tuleap is prone to a remote command-execution vulnerability because the application fails to sufficiently sanitize input data.
An attacker may leverage this issue to execute arbitrary commands in the context of the affected application.
Enalean Tuleap 7.4.99.5 and prior are vulnerable.
Exploit / POC
Enalean Tuleap 'svn/viewvc.php' Remote Command Execution Vulnerability
Attackers can exploit this issue using browser.
Attackers can exploit this issue using browser.
Solution / Fix
Enalean Tuleap 'svn/viewvc.php' Remote Command Execution Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
Enalean Tuleap 'svn/viewvc.php' Remote Command Execution Vulnerability
References:
References: